AgentTesla samples seen in MalwareBazaar
Agent Tesla steals information from browsers and email software. It can capture screenshots and clipboard contents.
Background
CISA and ACSC's 2022 overview describes delivery through phishing email attachments. That is documented family behavior, not a verified delivery route for every sample below.
What to do
If your antivirus reports Agent Tesla, open its detection history to see whether the threat was blocked, quarantined or still needs action. If you use Microsoft Defender on Windows, open Windows Security > Virus & threat protection > Protection history. If the status is Threat found - action needed, follow Defender's recommended action. Threat blocked means Defender reports it removed that threat. Keep a quarantined file quarantined; do not choose Allow on device.
If Agent Tesla ran, stop using that device for passwords or banking and contact IT on a work device. On a personal Windows device, run a full antivirus scan and follow its removal instructions. From a clean device, change passwords stored or entered on the infected device. Removing malware does not undo stolen credentials. Follow the affected service's account recovery steps.
Feed records
MalwareBazaar listed 1 file sample tagged AgentTesla among the 100 uploads checked for this report. This is a count of feed entries, not infected devices. The background above was checked on 2026-09-08; the feed records have their own observation dates.