AgentTesla and OriginLogger are closely related Windows information stealers. This January 2024 article examines their shared history, configuration data, and methods for exfiltrating credentials and other stolen information.
The research analyzes more than 1,500 configurations collected over the preceding three months. Email remained the most common exfiltration method in that collection, while Telegram accounted for a substantial minority. The article also explores what the available infection telemetry suggests about affected systems.
Configurations are an approximate proxy for campaigns. The results describe the collected samples and telemetry, with the limits of that visibility, rather than every AgentTesla or OriginLogger deployment.
