
"Reverse engineering analysis of Agent Tesla, a .NET-based info-stealer that uses APC injection, token manipulation, and registry persistence. Includes NtQueueApcThread, NtProtectVirtualMemory, and full payload extraction."
The x64dbg memory dump reveals that Agent Tesla uses Native API (NT API) calls for low-level operations, including APC (Asynchronous Procedure Call) injection.
NtQueueApcThread – Injects code into a target thread via APC.NtReadVirtualMemory – Reads memory from other processes.NtQuerySystemInformation – Collects system information.NtCreateThreadEx (likely present) – Creates threads for execution.
x64dbg hex dump showing NtQueueApcThread, NtReadVirtualMemory, and NtQuerySystemInformation.
The x64dbg dump reveals that Agent Tesla uses token manipulation and memory protection functions to gain elevated privileges and execute its payload.
NtOpenThreadToken – Opens thread tokens for privilege escalation.NtProtectVirtualMemory – Changes memory page protection for payload execution.NtOpenTimer – Opens timer objects for scheduled tasks.NtPowerInformation – Queries power state (anti-sandbox).NtQueryBootEntry – Retrieves boot information.
x64dbg hex dump showing NtOpenThreadToken, NtProtectVirtualMemory, and NtOpenTimer.
The x64dbg dump reveals that Agent Tesla can terminate processes and threads, as well as load/unload kernel drivers.
NtTerminateProcess – Terminates processes (e.g., EDR/AV).NtTerminateThread – Terminates threads.NtUnloadDriver – Unloads a kernel driver.NtUnmapViewOfSection – Unmaps memory sections (cleans traces).NtWaitForSingleObject – Synchronizes thread/process operations.
x64dbg hex dump showing NtTerminateProcess, NtUnloadDriver, and NtUnmapViewOfSection.
The .text section of the memory dump contains the full payload of Agent Tesla, confirming its capabilities as a comprehensive info-stealer.
OpenClipboard, SetClipboardData, EmptyClipboardCreateWindowExW, ShowWindow, SetWindowTextWDeleteFileW, FindFirstFileW, ReadFileGlobalAlloc, LoadLibraryExW, GetModuleHandleWCreateFontIndirectW, CreateBrushIndirect, SelectObject
Binary Ninja view of the .text section showing the full list of Windows APIs used by Agent Tesla.
The extended payload list reveals Agent Tesla's ability to manipulate the Windows Registry, manage tokens, and interact with COM objects.
RegOpenKeyExW, RegSetValueExW, RegDeleteKeyW – Persistence and configuration.OpenProcessToken, AdjustTokenPrivileges – Privilege escalation.CoCreateInstance, OleInitialize – Windows system interaction.SHFileOperationW, ShellExecuteExW, SHBrowseForFolderW – File and folder operations.
Binary Ninja view showing Registry, Token, and COM-related APIs.
This analysis uncovered Agent Tesla, a .NET-based info-stealer that combines advanced injection techniques, token manipulation, and registry persistence.
NtQueueApcThread for stealthy process injection.NtOpenThreadToken and AdjustTokenPrivileges for privilege escalation.RegSetValueExW for startup persistence..text section contained a comprehensive API list, confirming its info-stealer nature.NtQueueApcThread and NtReadVirtualMemory calls.NtOpenThreadToken and AdjustTokenPrivileges for privilege escalation attempts.RegSetValueExW and RegOpenKeyExW from unusual processes..text sections for large API lists (e.g., USER32.dll, KERNEL32.dll, ADVAPI32.dll).The analyzed Agent Tesla sample is available on MalwareBazaar for those who wish to conduct their own analysis:
🔗 Agent Tesla Sample on MalwareBazaar
Tools Used: x64dbg, Binary Ninja, Process Hacker