---
title: "Unmasking Agent Tesla: A Deep Dive into a Multi-Stage Campaign"
url: https://daily.dev/posts/unmasking-agent-tesla-a-deep-dive-into-a-multi-stage-campaign-kvh8icion
source_url: https://feeds.fortinet.com/~/948470225/0/fortinet/blog/threat-research~Unmasking-Agent-Tesla-A-Deep-Dive-into-a-MultiStage-Campaign
type: article
source: "FortiGuard Threat Research"
published: 2026-05-31T07:44:09.838Z
updated: 2026-05-31T08:29:40.226Z
tags: ["malware", "phishing", "powershell"]
reading_time: 4
upvotes: 0
comments: 0
language: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Unmasking Agent Tesla: A Deep Dive into a Multi-Stage Campaign

**[FortiGuard Threat Research](https://daily.dev/sources/fortiguard-threat-research)** · 4 min read · 0 upvotes · 0 comments

## Summary

FortiGuard Labs breaks down a multi-stage Agent Tesla campaign targeting Windows users. The infection chain starts with a business-themed phishing email containing a RAR attachment with a JScript loader (.jse). The loader fetches an encrypted PowerShell script from catbox.moe, which then performs process hollowing against the legitimate aspnet_compiler.exe to inject the Agent Tesla payload entirely in memory. Anti-analysis checks probe for VMware, VirtualBox, and Hyper-V environments before proceeding to credential harvesting — extracting browser cookies and stored passwords — and exfiltrating data via SMTP. IOCs, MITRE ATT&CK TTPs, and Fortinet product detections are provided.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://feeds.fortinet.com/~/948470225/0/fortinet/blog/threat-research~Unmasking-Agent-Tesla-A-Deep-Dive-into-a-MultiStage-Campaign>

## Similar posts on daily.dev

- [Threat Actors Weaponize AI Hype to Deliver AsyncRAT](https://daily.dev/posts/threat-actors-weaponize-ai-hype-to-deliver-asyncrat-mwevh7dcd) · FortiGuard Threat Research · 0 upvotes · 0 comments
- [The TTF Trap: A Global Campaign of a Low-Detection Lua Loader](https://daily.dev/posts/the-ttf-trap-a-global-campaign-of-a-low-detection-lua-loader-swccvjsbt) · FortiGuard Threat Research · 3 upvotes · 0 comments
- [Inside .NET Loader Analysis: From Malspam to In-Memory Loader](https://daily.dev/posts/inside-net-loader-analysis-from-malspam-to-in-memory-loader-tafajwltg) · Huntress Blog · 4 upvotes · 0 comments
- [Stealth in Layers: Unmasking the Loader used in Targeted Email Campaigns](https://daily.dev/posts/stealth-in-layers-unmasking-the-loader-used-in-targeted-email-campaigns-xfgpoq8c1) · Cyble · 0 upvotes · 0 comments

---

Tags: [#malware](https://daily.dev/tags/malware), [#phishing](https://daily.dev/tags/phishing), [#powershell](https://daily.dev/tags/powershell)

[View this post on daily.dev](https://daily.dev/posts/unmasking-agent-tesla-a-deep-dive-into-a-multi-stage-campaign-kvh8icion)
