[![Logo](https://www.paloaltonetworks.com/wp-content/uploads/2021/07/PANW_Parent.png)](https://www.paloaltonetworks.com/)  
[![Unit42 Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/unit42-logo-white.svg)](https://unit42.paloaltonetworks.com/)  
Menu

* [Tools](https://unit42.paloaltonetworks.com/tools/)
* [ATOMs](https://unit42.paloaltonetworks.com/atoms/)
* [Security Consulting](https://www.paloaltonetworks.com/unit42)
* [About Us](https://unit42.paloaltonetworks.com/about-unit-42/)
* [**Under Attack?**](https://start.paloaltonetworks.com/contact-unit42.html)
* [Threat Research Center](https://unit42.paloaltonetworks.com "Threat Research")
* [Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/ "Threat Research")
* [Malware](https://unit42.paloaltonetworks.com/category/malware/ "Malware")  
  [Malware](https://unit42.paloaltonetworks.com/category/malware/)

# Analyzing the Various Layers of AgentTesla's Packing

![Clock Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-clock.svg) 10 min read

* ![Profile Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-profile-grey.svg)  
  By:
  
  * [Jeff White](https://unit42.paloaltonetworks.com/author/jeff-white/)

* ![Published Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-calendar-grey.svg)  
  Published:September 25, 2017

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-category.svg)  
  Categories:
  
  * [Malware](https://unit42.paloaltonetworks.com/category/malware/)
  * [Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/)

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-tags-grey.svg)  
  Tags:
  
  * [.NET](https://unit42.paloaltonetworks.com/tag/net/)
  * [AgentTesla](https://unit42.paloaltonetworks.com/tag/agenttesla/)
  * [DnSpy](https://unit42.paloaltonetworks.com/tag/dnspy/)

* [![Download Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-download.svg)](https://unit42.paloaltonetworks.com/unit42-analyzing-various-layers-agentteslas-packing/?pdf=download&lg=en&_wpnonce=40dbae5d0f "Click here to download")

* [![Print Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-print.svg)](https://unit42.paloaltonetworks.com/unit42-analyzing-various-layers-agentteslas-packing/?pdf=print&lg=en&_wpnonce=40dbae5d0f "Click here to print")

Share![Down arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/down-arrow.svg)

* ![Link Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-share-link.svg)
* [![Link Email](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-sms.svg)](mailto:?subject=Analyzing%20the%20Various%20Layers%20of%20AgentTesla’s%20Packing&body=Check%20out%20this%20article%20https%3A%2F%2Funit42.paloaltonetworks.com%2Funit42-analyzing-various-layers-agentteslas-packing%2F "Share in email")
* [![Facebook Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-fb-share.svg)](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Funit42.paloaltonetworks.com%2Funit42-analyzing-various-layers-agentteslas-packing%2F "Share in Facebook")
* [![LinkedIn Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-linkedin-share.svg)](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Funit42-analyzing-various-layers-agentteslas-packing%2F&title=Analyzing%20the%20Various%20Layers%20of%20AgentTesla’s%20Packing "Share in LinkedIn")
* [![Twitter Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-twitter-share.svg)](https://twitter.com/intent/tweet?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Funit42-analyzing-various-layers-agentteslas-packing%2F&text=Analyzing%20the%20Various%20Layers%20of%20AgentTesla’s%20Packing "Share in Twitter")
* [![Reddit Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-reddit-share.svg)](https://www.paloaltonetworks.com//www.reddit.com/submit?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Funit42-analyzing-various-layers-agentteslas-packing%2F&ts=markdown "Share in Reddit")
* [![Mastodon Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-mastodon-share.svg)](https://mastodon.social/share?text=Analyzing%20the%20Various%20Layers%20of%20AgentTesla’s%20Packing%20https%3A%2F%2Funit42.paloaltonetworks.com%2Funit42-analyzing-various-layers-agentteslas-packing%2F "Share in Mastodon")
  AgentTesla is a fairly popular key logger built using the [Microsoft .NET Framework](https://en.wikipedia.org/wiki/.NET_Framework) and has shown a substantial rise in usage over the past few months.

![agenttesla\_1](https://unit42.paloaltonetworks.com/wp-content/uploads/2017/09/agenttesla_1.png)

It offers all of the standard features of a keylogger but goes beyond the typical confines of this type of software. One particular feature of interest is the custom packer it uses to hide the primary AgentTesla binary. Packers allow for a binary to essentially be wrapped in another binary to mask the original one from detection.

There are a number of excellent blogs out there covering [AgentTesla's functionality](https://www.google.com/url?sa=t&rct=j&q=&esrc=s&source=web&cd=11&cad=rja&uact=8&ved=0ahUKEwiuguS2j4PWAhXkzIMKHWy1Ass4ChAWCCcwAA&url=https%3A%2F%2Fblog.fortinet.com%2F2017%2F06%2F28%2Fin-depth-analysis-of-net-malware-javaupdtr&usg=AFQjCNG0sqBMWMMIo) and it's [various obfuscations](https://blogs.forcepoint.com/security-labs/part-two-camouflage-netting), but having I recently unpacked a sample and wanted to focus on this particular function and provide some helpful tools to aide in unpacking it.

For this analysis, I'll be using a PE32 version AgentTesla file seen in the wild on August 29^th^ with hash "ca29bd44fc1c4ec031eadf89fb2894bbe646bc0cafb6242a7631f7404ef7d15c". You'll find AgentTesla delivered commonly via [phishing documents](https://cysinfo.com/agent-tesla-new-spyware-variant-plucked-hackers-arena/) that usually contain VBA macros to download and run a file -- like the one in question.

As it's a commercial product, you'll find a lot of variety in the initial carrier files that deliver the AgentTesla binary; however, at some point you'll find yourself with a PE.

## Thus, begins the journey...

I suppose the first layer of obfuscation really begins with the file itself, called "one.jpeg.png.exe" and an icon of a JPG trying to create an illusion of legitimacy.

![agenttesla\_2](https://unit42.paloaltonetworks.com/wp-content/uploads/2017/09/agenttesla_2.png)

This is a common technique to fool people and they've taken it one step further by opening an image when you execute the binary.

![agenttesla\_3](https://unit42.paloaltonetworks.com/wp-content/uploads/2017/09/agenttesla_3.png)

The first executable is a .NET application, which is no surprise since AgentTesla is very well known for being a .NET key logger. To analyze .NET applications, I prefer to use the application dnSpy and, once loading up this sample, we can see there is only one namespace of interest with a handful of functions and a byte array.

![agenttesla\_4](https://unit42.paloaltonetworks.com/wp-content/uploads/2017/09/agenttesla_4.png)

The Japanese kanji stands out at first glance but I believe this is less about language and more about being a form of obfuscation -- I'll explain why shortly.

Looking at the Main() function shows a pattern of multiple calls to two other functions.

![agenttesla\_5](https://unit42.paloaltonetworks.com/wp-content/uploads/2017/09/agenttesla_5.png)

Take for example the below string.  
ゆ.く(ゆ.るこ(New Byte() { 129, 148, 157, 176, 144, 129, 163, 219 })),

|---|-------------------------------------------------------------------|
| 1 | ゆ.く(ゆ.るこ(New Byte() { 129, 148, 157, 176, 144, 129, 163, 219 })), |

The namespace is "ゆ" and the functions are "く" and "るこ", with the latter taking a byte array as input and then the resulting output of that function being passed to the former.

Starting with the first function, there are two XOR operations that occur with what looks like two values from the passed in byte array and then a static XOR key.  
![agenttesla\_6](https://unit42.paloaltonetworks.com/wp-content/uploads/2017/09/agenttesla_6.png)

Looking at this function deeper, it uses the last value in the byte array as one of the 3 XOR keys, then adjusts the array in size and begins the decoding loop. Starting at the first byte, it will take this number as the second XOR key and increment it each iteration. The final XOR key is pulled from the GetBytes call on the long string of kanji.

Before going any further though, can you spot the issue with the function above? It works and successfully decodes the byte array but there is a flaw in codes logic that threw me for a loop when trying to implement the code in Python.

If you manually XOR those values together (129 \[first byte\] ^ 214 \[last byte\] ^ 12375 \[first kanji\]), the resulting output isn't what gets returned within the debugger. In fact, it's not even close which left me scratching my head for a while.  
129^214^12375 = 12288 (0x3000)

|---|----------------------------------|
| 1 | 129^214^12375 = 12288 (0x3000) |

Instead, what we end up with is 104 (0x68). It's clearly wrong though and I assumed I was missing something in what appeared to be a relatively straight forward, par for the course, decoding function. If I XOR the know good result with the two values from the byte array, I end up with 63 (0x3F), otherwise known as "?".

What's happening is that the GetBytes call is set to use the default system encoding, which in my case is Windows-1252, so the bytes fall outside of the acceptable range and all return as 63 (0x3F), regardless of where the index pointer is in the array. Given this, the only two values I ever need to worry about are within the array itself and I can ignore most of this code.

Below is a small Python script which will decode the strings passed into it.  
def decode(a): xorkey = a\[-1\] a = a\[0:-1\] b = \[0\] \* len(a) num = 0 counter = 0 maxlength = len(b) - 1 while counter \<= maxlength: b\[len(b) - 1 - counter\] = chr(a\[counter\] ^ xorkey ^ 0x3f) counter += 1 return "".join(b) \>\>\> a = \[129,148,157,176,144,129,163,219\] \>\>\> decode(a) 'GetType'

|-------------------------------------|--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 | def decode(a): xorkey = a\[-1\] a = a\[0:-1\] b = \[0\] \* len(a) num = 0 counter = 0 maxlength = len(b) - 1 while counter \<= maxlength: b\[len(b) - 1 - counter\] = chr(a\[counter\] ^ xorkey ^ 0x3f) counter += 1 return "".join(b) \>\>\> a = \[129,148,157,176,144,129,163,219\] \>\>\> decode(a) 'GetType' |

As the string successfully decodes with using XOR key 0x3F, it implies it was also encoded with this value initially, so the default code page used by the author when encoding it was also most likely Windows-1252.

The reason I believe the kanji is more for obfuscation than anything else is because of this and what the XOR key displays, which is nothing but a jumble of random characters without any coherent message.

This randomness in function and variable names is similar to the techniques they use in later payloads but now with a different character set.

For the second function, "く" it simply returns a string from the byte array of the previous function.

Going back to the previously mentioned byte array, it's quite large and only has one reference inside this code, highlighted below.  
![agenttesla\_7](https://unit42.paloaltonetworks.com/wp-content/uploads/2017/09/agenttesla_7.png)

After the byte array is passed to the decoding function, the output is used as input into a new function, "うむれぐ", that is responsible for decompressing the data.

![agenttesla\_8](https://unit42.paloaltonetworks.com/wp-content/uploads/2017/09/agenttesla_8.png)

Once decompressed, the new data is returned in a byte array.

At this point I copied out the list of integers for the byte array and ran it through the decoding Python function and decompressed the it with the zlib library into the next payload.  
fh = open("output", "w") fh.write(zlib.decompress(decode(a), -15)) fh.close()

|-------|-------------------------------------------------------------------------------|
| 1 2 3 | fh = open("output", "w") fh.write(zlib.decompress(decode(a), -15)) fh.close() |

Looking at the new file shows that it is a DLL named "rp.dll".  
![agenttesla\_9](https://unit42.paloaltonetworks.com/wp-content/uploads/2017/09/agenttesla_9.png)

This was also a .NET file and we can load it into dnSpy for further analysis; however, before doing that I'll go over the final part of the first packer.  
Dim objectValue As Object = RuntimeHelpers.GetObjectValue(NewLateBinding.LateGet(Nothing,CType(NewLateBinding.LateGet(Nothing, "System.Type","GetType", "System.Reflection.Assembly", Nothing, Nothing, Nothing), Type), "Load", BINARY\_ARRAY, Nothing, Nothing, Nothing)) Dim objectValue2 As Object = RuntimeHelpers.GetObjectValue(NewLateBinding.LateGet(RuntimeHelpers.GetObjectValue(objectValue), Nothing, "GetType", "とむ暮.とむ暮", Nothing, Nothing, Nothing)) NewLateBinding.LateGet(Nothing, CType(NewLateBinding.LateGet(Nothing, Type.\[GetType\]("System.Type", "GetType", "System.Activator", Nothing, Nothing, Nothing), Type), "CreateInstance", New Object() { RuntimeHelpers.GetObjectValue(objectValue2) }, Nothing, Nothing, Nothing)

|-----------|--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| 1 2 3 4 5 | Dim objectValue As Object = RuntimeHelpers.GetObjectValue(NewLateBinding.LateGet(Nothing,CType(NewLateBinding.LateGet(Nothing, "System.Type","GetType", "System.Reflection.Assembly", Nothing, Nothing, Nothing), Type), "Load", BINARY\_ARRAY, Nothing, Nothing, Nothing)) Dim objectValue2 As Object = RuntimeHelpers.GetObjectValue(NewLateBinding.LateGet(RuntimeHelpers.GetObjectValue(objectValue), Nothing, "GetType", "とむ暮.とむ暮", Nothing, Nothing, Nothing)) NewLateBinding.LateGet(Nothing, CType(NewLateBinding.LateGet(Nothing, Type.\[GetType\]("System.Type", "GetType", "System.Activator", Nothing, Nothing, Nothing), Type), "CreateInstance", New Object() { RuntimeHelpers.GetObjectValue(objectValue2) }, Nothing, Nothing, Nothing) |

I've cleaned up the encoded strings so you can see what it's doing but effectively, it takes the DLL assembly, loads it, and calls the main function, "とむ暮.とむ暮", within it.

This DLL uses the same byte array string obfuscation as the initial executable.  
![agenttesla\_10](https://unit42.paloaltonetworks.com/wp-content/uploads/2017/09/agenttesla_10.png)

In the above image, you can see it begins by checking whether the file "\\\\Products\\\\WinDecode.exe" exists and then will create the "\\\\Products\\\\" directory if it does not. After that it will enumerate processes to kill, delete files, establish itself in the registry for persistence and other characteristics typical of this malware.

![agenttesla\_11](https://unit42.paloaltonetworks.com/wp-content/uploads/2017/09/agenttesla_11.png)

But, eventually during the execution, you'll end up at the next part of the unpacking code.  
Dim obj2 As Object = とむ暮.れなつ(Me.まこうに(Me.こなき(Me.れな()))) Dim うひ硯る As うひ硯る = New うひ硯る() Return うひ硯る.う("Nothing", String.Empty, CType(obj2, Byte()), True)

|-------|--------------------------------------------------------------------------------------------------------------------------------------------------------|
| 1 2 3 | Dim obj2 As Object = とむ暮.れなつ(Me.まこうに(Me.こなき(Me.れな()))) Dim うひ硯る As うひ硯る = New うひ硯る() Return うひ硯る.う("Nothing", String.Empty, CType(obj2, Byte()), True) |

The first line calls multiple functions - starting on the far right is "れな". This function can be seen below and creates an object from a PNG file in the resources section of the DLL.

![agenttesla\_12](https://unit42.paloaltonetworks.com/wp-content/uploads/2017/09/agenttesla_12.png)

## Picture Time

The PNG itself doesn't visually show anything of note but static.

![agenttesla\_13](https://unit42.paloaltonetworks.com/wp-content/uploads/2017/09/agenttesla_13.png)

The next function "こなき" is a bit more interesting.

![agenttesla\_14](https://unit42.paloaltonetworks.com/wp-content/uploads/2017/09/agenttesla_14.png)

This loads the image as a bitmap and then it will read the pixels in a certain order to build an array from the values for Red, Green, and Blue that get returned.

For example, if you look at the bottom left of the image (0,192), you will see a dark green with the hex value 0x1AE2C.

![agenttesla\_15](https://unit42.paloaltonetworks.com/wp-content/uploads/2017/09/agenttesla_15.png)

The first entries in the array would be 0x2C (Blue), 0xAE (Green), 0x1 (Red)

To unpack this, I once again re-wrote the code in Python and used the Python Imaging Library (PIL) to extract the bytes. This particular image is 192x192 pixels and 24bits per pixel (3 bytes -- RGB) and it iterates over each pixel from left to right, bottom to top, for the array of data.  
from PIL import Image im = Image.open("/Users/pickleRICK/19.png") def imparse(a): width, height = im.size counter = 0 b = \[0\] \* (width \* height \* 3) for y in range(height - 1, -1, -1): for x in range(0,width): pixel = im.getpixel((x,y)) b\[counter \* 3 + 2\] = pixel\[0\] # R b\[counter \* 3 + 1\] = pixel\[1\] # G b\[counter \* 3 + 0\] = pixel\[2\] # B counter += 1 while b\[-1\] == 0: del b\[-1\] return b

|-------------------------------------------|------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 | from PIL import Image im = Image.open("/Users/pickleRICK/19.png") def imparse(a): width, height = im.size counter = 0 b = \[0\] \* (width \* height \* 3) for y in range(height - 1, -1, -1): for x in range(0,width): pixel = im.getpixel((x,y)) b\[counter \* 3 + 2\] = pixel\[0\] # R b\[counter \* 3 + 1\] = pixel\[1\] # G b\[counter \* 3 + 0\] = pixel\[2\] # B counter += 1 while b\[-1\] == 0: del b\[-1\] return b |

After it returns, the byte array gets passed to the now familiar decode function and then the deflate function.  
\&gt;\&gt;\&gt; dec = imparse(im) \&gt;\&gt;\&gt; dec \[44, 174, 1, 0, 237, 11, 8, 125, 109, 41, 15, ... \&gt;\&gt;\&gt; dec = decode(dec) \&gt;\&gt;\&gt; dec '\\xec\\xbd\\tx\\x1c\\xc5\\x95\\x00\\xdcs\\xf59#\\xa9\\xa6G ... \&gt;\&gt;\&gt; dec = zlib.decompress(dec,-15) \&gt;\&gt;\&gt; dec 'MZ\\x90\\x00\\x03\\x00\\x00\\x00\\x04\\x00\\x00\\x00\\xff\\xff\\x00 ...

|-------------------------|----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| 1 2 3 4 5 6 7 8 9 10 11 | \&gt;\&gt;\&gt; dec = imparse(im) \&gt;\&gt;\&gt; dec \[44, 174, 1, 0, 237, 11, 8, 125, 109, 41, 15, ... \&gt;\&gt;\&gt; dec = decode(dec) \&gt;\&gt;\&gt; dec '\\xec\\xbd\\tx\\x1c\\xc5\\x95\\x00\\xdcs\\xf59#\\xa9\\xa6G ... \&gt;\&gt;\&gt; dec = zlib.decompress(dec,-15) \&gt;\&gt;\&gt; dec 'MZ\\x90\\x00\\x03\\x00\\x00\\x00\\x04\\x00\\x00\\x00\\xff\\xff\\x00 ... |

As you can see, we have the MZ header and the next binary.

Within the DLL are additional functions which handle executing the new payload and I've gone ahead and decoded some of the native API's they use to show how they carry out activity.  
![AgentTesla21](https://unit42.paloaltonetworks.com/wp-content/uploads/2017/09/AgentTesla21.png)

## The final payload

Arrival of the last binary -- another .NET application called "RII9DKFR5LC4Y669MLOA2C50SFLPHZBN61CZ160Z.exe". If you read any of the posts mentioned earlier on the analysis of AgentTesla, then this will look familiar.

![agenttesla\_16](https://unit42.paloaltonetworks.com/wp-content/uploads/2017/09/agenttesla_16.png)

Function and variable names are encoded with Unicode values in the range of 0x200B-0x200E. Strings are decrypted by, in this sample, function "KMBHFDXSELJYYLVK\\u3002".

![agenttesla\_17](https://unit42.paloaltonetworks.com/wp-content/uploads/2017/09/agenttesla_17.png)

This function uses a hardcoded password and salt to derive a key from the SHA1 hashing algorithm as implemented by Microsoft (modified PBKDF1). Afterwards, it uses the key and hardcoded IV to decrypt the string with AES-CBC.

![agenttesla\_18](https://unit42.paloaltonetworks.com/wp-content/uploads/2017/09/agenttesla_18.png)

A quick Google for that IV shows hundreds of results for it, with most revolving around an encryption example that was used as the base for this function -- it even copies the examples variable names.

What I found interesting here is that none of these values ever change sample to sample. Even going back to the samples in the write-ups on AgentTesla from over 6 months ago, I was able to decrypt their base64 strings listed in the blog. This confirms the same values are in use and likely hard coded into the builder for AgentTesla.

Given that everything is static then, it's fairly trivial to extract all of the base64 encoded strings, decrypt them, and look for interesting IoC's.  
from Crypto.Cipher import AES def stringdecrypt(a): string = base64.b64decode(a) iv = "@1B2c3D4e5F6g7H8" key = "\\x34\\x88\\x6D\\x5B\\x09\\x7A\\x94\\x19\\x78\\xD0\\xE3\\x8b\\x1b\\x5c\\xa3\\x29\\x60\\x74\\x6a\\x5e\\x5d\\x64\\x87\\x11\\xb1\\x2c\\x67\\xaa\\x5b\\x3a\\x8e\\xbf" #to 6a/5e for first iteration cleartext = AES.new(key\[0:32\], AES.MODE\_CBC, iv).decrypt(string) return cleartext fh = open("extractedb64") content = fh.readlines() fh.close() for i in content: try: dec = stringdecrypt(i) print "%s | %s" % (i.strip(),dec.strip()) except: pass

|-------------------------------------------|-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 | from Crypto.Cipher import AES def stringdecrypt(a): string = base64.b64decode(a) iv = "@1B2c3D4e5F6g7H8" key = "\\x34\\x88\\x6D\\x5B\\x09\\x7A\\x94\\x19\\x78\\xD0\\xE3\\x8b\\x1b\\x5c\\xa3\\x29\\x60\\x74\\x6a\\x5e\\x5d\\x64\\x87\\x11\\xb1\\x2c\\x67\\xaa\\x5b\\x3a\\x8e\\xbf" #to 6a/5e for first iteration cleartext = AES.new(key\[0:32\], AES.MODE\_CBC, iv).decrypt(string) return cleartext fh = open("extractedb64") content = fh.readlines() fh.close() for i in content: try: dec = stringdecrypt(i) print "%s | %s" % (i.strip(),dec.strip()) except: pass |

What we end up with is a long list of values like the below.  
cWUeT8dJU4KfzxUEgGflzQ== | temp y9/s0/2Soj9dWZ7YCF9viw== | \\des\_date.txt hQ1zQ5Cg31OSE+BZ2Os36w== | 2017-08-25 cWUeT8dJU4KfzxUEgGflzQ== | temp y9/s0/2Soj9dWZ7YCF9viw== | \\des\_date.txt 1IhffSZWWBl13XPDs8n3myYCTMqLedaSKEkL/imL258= | dd.MM.yyyy HH:mm:ss cWUeT8dJU4KfzxUEgGflzQ== | temp aXsej6rp5uxy+3ym08w3iA== | ApplicationData haLsi+cj0yodiuWmM+o4Wg== | appdata AnV66gJ6ewY8YTWIByRSMA== | Temp cWUeT8dJU4KfzxUEgGflzQ== | temp zYMGsY8aSA781gMxSStsC9UAfia6hLdLRxgBeS3NtD0= | \\Java\\JavaUpdtr.exe cWUeT8dJU4KfzxUEgGflzQ== | temp y9/s0/2Soj9dWZ7YCF9viw== | \\des\_date.txt Akq+/Qobe3bW+jdjmv5oI6h1rNqdq+rlANdh6Ef29KelgAp0y6gsCspLDS+k+xmNC9TpnFhgwZyL///RhoSWxQ== | Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows aZG83zDiQxysOvFJFc8qmg== | Load 8mFIzTz8+GxS3SBdy62qeA== | JavaUpdtr IMqa7/uMjEFhAZrJPRn9Gw== | False qQj4VB+mzRT8iDf7llcE6Q== | xyz hyNN5z+7qAsS695lDXLuHg== | True ... 82ZGUDSQrPCv8v1Hf+HpRA== | \&lt;/span\&gt; BJsW0oB1ieLYwE8A0Yu6OlLBTcrh0varR+ibOkyOCrk= | mylogbox4h@gmail.com 2qbrW8tf2IZoaPGZlcaKWw== | /log.tmp v4EpbnhZTubu6HTjEZ8Gdw== | \[SavedLog ( I/tDnJPWEB6yySAivkY/576ixyY2gOP+bLVbbaRIV8A= | yyyy\_MM\_dd\_HH\_mm\_ss 2qbrW8tf2IZoaPGZlcaKWw== | /log.tmp Q9Yhy5Uive3G6Gspdid9EQ== | Saved\_Log\_From\_ eCqe8oqjGUIRwUWqnBrrpA== | / q542gy/+wDIUJhH3OGKnNg== | - 3TzIyOOSC+3lcpPaeTxO6g== | \_ 4T5LGk6qEvqUS2xRJLUlww== | .html

|----------------------------------------------------------------------------------------|----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 | cWUeT8dJU4KfzxUEgGflzQ== | temp y9/s0/2Soj9dWZ7YCF9viw== | \\des\_date.txt hQ1zQ5Cg31OSE+BZ2Os36w== | 2017-08-25 cWUeT8dJU4KfzxUEgGflzQ== | temp y9/s0/2Soj9dWZ7YCF9viw== | \\des\_date.txt 1IhffSZWWBl13XPDs8n3myYCTMqLedaSKEkL/imL258= | dd.MM.yyyy HH:mm:ss cWUeT8dJU4KfzxUEgGflzQ== | temp aXsej6rp5uxy+3ym08w3iA== | ApplicationData haLsi+cj0yodiuWmM+o4Wg== | appdata AnV66gJ6ewY8YTWIByRSMA== | Temp cWUeT8dJU4KfzxUEgGflzQ== | temp zYMGsY8aSA781gMxSStsC9UAfia6hLdLRxgBeS3NtD0= | \\Java\\JavaUpdtr.exe cWUeT8dJU4KfzxUEgGflzQ== | temp y9/s0/2Soj9dWZ7YCF9viw== | \\des\_date.txt Akq+/Qobe3bW+jdjmv5oI6h1rNqdq+rlANdh6Ef29KelgAp0y6gsCspLDS+k+xmNC9TpnFhgwZyL///RhoSWxQ== | Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows aZG83zDiQxysOvFJFc8qmg== | Load 8mFIzTz8+GxS3SBdy62qeA== | JavaUpdtr IMqa7/uMjEFhAZrJPRn9Gw== | False qQj4VB+mzRT8iDf7llcE6Q== | xyz hyNN5z+7qAsS695lDXLuHg== | True ... 82ZGUDSQrPCv8v1Hf+HpRA== | \&lt;/span\&gt; BJsW0oB1ieLYwE8A0Yu6OlLBTcrh0varR+ibOkyOCrk= | mylogbox4h@gmail.com 2qbrW8tf2IZoaPGZlcaKWw== | /log.tmp v4EpbnhZTubu6HTjEZ8Gdw== | \[SavedLog ( I/tDnJPWEB6yySAivkY/576ixyY2gOP+bLVbbaRIV8A= | yyyy\_MM\_dd\_HH\_mm\_ss 2qbrW8tf2IZoaPGZlcaKWw== | /log.tmp Q9Yhy5Uive3G6Gspdid9EQ== | Saved\_Log\_From\_ eCqe8oqjGUIRwUWqnBrrpA== | / q542gy/+wDIUJhH3OGKnNg== | - 3TzIyOOSC+3lcpPaeTxO6g== | \_ 4T5LGk6qEvqUS2xRJLUlww== | .html |

File names, registry keys, and e-mails to start off hunting with. You can also see where the corresponding base64 is within the code and then use dnSpy to obtain further context on how AgentTesla utilizes these values.

For example, below is something that stood out as interesting almost immediately.  
4nmIR8y7iw8axs2u6GfIQ8f/7fSpMKvqD0ODaew16nI= | mylogbox3h@gmail.com 5XDX6cForslWY791UzW+zw== | sammy1990 wf990RzBidRdPMgWIckJ2g== | smtp.gmail.com

|-------|-------------------------------------------------------------------------------------------------------------------------------------------------------|
| 1 2 3 | 4nmIR8y7iw8axs2u6GfIQ8f/7fSpMKvqD0ODaew16nI= | mylogbox3h@gmail.com 5XDX6cForslWY791UzW+zw== | sammy1990 wf990RzBidRdPMgWIckJ2g== | smtp.gmail.com |

Pivoting to these values in dnSpy will land you in a function that seems responsible for sending the stolen data back to the attacker.  
![agenttesla\_19](https://unit42.paloaltonetworks.com/wp-content/uploads/2017/09/agenttesla_19.png)

## Pivoting on a hunch

At this point, I've accomplished the goal I set out for -- covering the packing techniques used by the current version of AgentTesla, offering some code to automate unpacking and decrypt some configuration data.

But why stop when you're ahead?

I like to Google static values and constants when analyzing malware because you can usually find some interesting stuff -- configurations, forums, accounts, panels, etc. When I began searching for the file "one.jpeg.png.exe" I stumbled across a site, "b-f-v\[.\]info", which hosts various versions of this keylogger.

![agenttesla\_20](https://unit42.paloaltonetworks.com/wp-content/uploads/2017/09/agenttesla_20.png)

They all function in the same way but the image that displays is related to the first part of the file name. The images are various sizes so the decoding would be different for each; however, the code shown previously will grab the correct Width and Height for building the array.

Also take note of the dates and when they were modified. The sample covered in this blog was seen on August 29^th^, just two days before these were created -- so the person or group behind these appear to be actively creating new versions to send out. I confirmed in these samples we find the same SMTP credentials.

## Conclusion

Hopefully this overview of their packing techniques, along with the scripts to unpack each phase, prove helpful to others when looking at AgentTesla. Given its recent spikes in popularity, it's likely not going anywhere anytime soon so the more knowledge you have of the threat, the better you can defend yourself.

You can continue to track this threat through the [Palo Alto Networks AutoFocus AgentTesla tag](https://autofocus.paloaltonetworks.com/) and you will find the hashes for all of the files covered in this blog below:

### **Indicators of Compromise**

Initial PE32

one.jpeg.png.exe | ca29bd44fc1c4ec031eadf89fb2894bbe646bc0cafb6242a7631f7404ef7d15c

mypic.jpeg.png.exe | cb0de059cbd5eba8c61c67bedcfa399709e40246039a0457ca6d92697ea516f9

familyhome.jpeg.png.exe / myhome.jpeg.png.exe | 444e9fbf683e2cff9f1c64808d2e6769c13ed6b29899060d7662d1fe56c3121b

gift-certificate.pdf.png.exe | 124bb13ede19e56927fe5afc5baf680522586534727babbe1aa1791d116caeeb

request-for-quotation.pdf.png.exe | dce91ff60c8d843c3e5845061d6f73cfc33e34a5b8347c4d9c468911e29c3ce6

### **DLL's**

rp.dll | 3c48c7f16749126a06c2aae58ee165dc72df658df057b1ac591a587367eae4ad

rp.dll | a5768f1aa364d69e47351c81b1366cc2bfb1b67a0274a56798c2af82ae3525a8

### **Second stage encoded images**

19\.png | e42a0fb66dbf40578484566114e5991cf9cf0aa05b1bd080800a55e1e13bff9e

72\.png | cd64f1990d3895cb7bd69481186d5a2b1b614ee6ac453102683dba8586593c03

### **AgentTesla**

RII9DKFR5LC4Y669MLOA2C50SFLPHZBN61CZ160Z.exe | 3e588ec87759dd7f7d34a8382aad1bc91ce4149b5f200d16ad1e9c1929eec8ec

B92MKZFESR6J7R2PNQ9ZTBA6QN0LIEXTUQEVH3T3.exe | 8fb72967b67b5a224c0fcfc10ab939999e5dc2e877a511875bd4438bcc2f5494
Back to top

### Tags

* [.NET](https://unit42.paloaltonetworks.com/tag/net/ ".NET")
* [AgentTesla](https://unit42.paloaltonetworks.com/tag/agenttesla/ "AgentTesla")
* [DnSpy](https://unit42.paloaltonetworks.com/tag/dnspy/ "dnSpy")  
  [Threat Research Center](https://unit42.paloaltonetworks.com "Threat Research") [Next: 2 Minute Threat Brief: Android Toast Overlay Attack](https://unit42.paloaltonetworks.com/unit42-2-minute-threat-brief-android-toast-overlay-attack/ "2 Minute Threat Brief: Android Toast Overlay Attack")

### Table of Contents

* 

### Related Articles

* [Analyzing the Current State of AI Use in Malware](https://unit42.paloaltonetworks.com/ai-use-in-malware/ "article - table of contents")
* [Suspected Nation-State Threat Actor Uses New Airstalk Malware in a Supply Chain Attack](https://unit42.paloaltonetworks.com/new-windows-based-malware-family-airstalk/ "article - table of contents")
* [PhantomVAI Loader Delivers a Range of Infostealers](https://unit42.paloaltonetworks.com/phantomvai-loader-delivers-infostealers/ "article - table of contents")

## Related Malware Resources

![Pictorial representation of post-exploitation identity misuse in SPIFFE/SPIRE. Close-up of a person wearing glasses, with computer code reflected in the lenses.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/09/12_Security-Technology_Category_1920x900-786x368.jpg)  
[![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) September 10, 2026 [#### The Machine With Many Faces: Post-Exploitation Identity Misuse in SPIFFE/SPIRE](https://unit42.paloaltonetworks.com/kubernetes-spiffe-spire-identity-spoofing/)

* [API](https://unit42.paloaltonetworks.com/tag/api/ "API")

* [Cryptographic](https://unit42.paloaltonetworks.com/tag/cryptographic/ "cryptographic")

* [JSON](https://unit42.paloaltonetworks.com/tag/json/ "JSON")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/kubernetes-spiffe-spire-identity-spoofing/ "The Machine With Many Faces: Post-Exploitation Identity Misuse in SPIFFE/SPIRE")  
  ![Pictorial representation of a pay-per-install threat group campaign prodiving infection service for spreading malware. A close-up of a computer circuit board with a central microchip is depicted. Red digital data streams in the form of glowing binary numbers and arrows appear to flow in and out of the chip, symbolizing data processing and transfer. The scene is illuminated with a futuristic blue and red glow.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/09/04_Malware_Category_1920x900-6-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) September 9, 2026 [#### Untracked Nightmares: The Threats Hiding Behind Commodity Infrastructure](https://unit42.paloaltonetworks.com/ppi-network-malware-campaign-analysis/)

* [ARKTunnel](https://unit42.paloaltonetworks.com/tag/arktunnel/ "ARKTunnel")

* [C2](https://unit42.paloaltonetworks.com/tag/c2/ "C2")

* [CL-CRI-1171](https://unit42.paloaltonetworks.com/tag/cl-cri-1171/ "CL-CRI-1171")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ppi-network-malware-campaign-analysis/ "Untracked Nightmares: The Threats Hiding Behind Commodity Infrastructure")  
  ![Pictorial representation of attackers using AI tools to target Latin American organizations. A vibrant cityscape with silhouettes of numerous people walking along a bustling street. The scene is illuminated by bright urban lights and digital-like particles, creating a dynamic and futuristic atmosphere.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/09/AdobeStock_768915868-2-1-786x373.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) September 3, 2026 [#### Attackers Expose Ongoing AI Tool Use Targeting Organizations in Latin America](https://unit42.paloaltonetworks.com/ai-tool-use-targeting-latam-orgs/)

* [Agentic AI](https://unit42.paloaltonetworks.com/tag/agentic-ai/ "Agentic AI")

* [ChatGPT](https://unit42.paloaltonetworks.com/tag/chatgpt/ "ChatGPT")

* [CL-CRI-1131](https://unit42.paloaltonetworks.com/tag/cl-cri-1131/ "CL-CRI-1131")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ai-tool-use-targeting-latam-orgs/ "Attackers Expose Ongoing AI Tool Use Targeting Organizations in Latin America")  
  ![Pictorial representation of vishing campaigns in Microsoft Teams. A digital image of a skull formed by blue binary code on a black background, with scattered ones and zeros and digital noise, symbolizes how stealthy prompt injection attacks can exploit AI logic to bypass security controls.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/01_Malware_Category_1920x900-5-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 31, 2026 [#### Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams](https://unit42.paloaltonetworks.com/spring-ring-voice-phishing-campaigns/)

* [Cloaked Ursa](https://unit42.paloaltonetworks.com/tag/cloaked-ursa/ "Cloaked Ursa")

* [Entra ID](https://unit42.paloaltonetworks.com/tag/entra-id/ "Entra ID")

* [Microsoft Teams](https://unit42.paloaltonetworks.com/tag/microsoft-teams/ "Microsoft Teams")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/spring-ring-voice-phishing-campaigns/ "Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams")  
  ![Pictorial representation of AI-enabled malware. A vibrant digital interface displaying various icons and graphs, resembling a futuristic network or data analysis dashboard. The scene is illuminated with glowing lights and patterns.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/AdobeStock_1270203474-2-1-786x368.png)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 25, 2026 [#### The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution](https://unit42.paloaltonetworks.com/ai-enabled-malware-analysis/)

* [Backdoor](https://unit42.paloaltonetworks.com/tag/backdoor/ "backdoor")

* [Bitcoin](https://unit42.paloaltonetworks.com/tag/bitcoin/ "Bitcoin")

* [DLL hijacking](https://unit42.paloaltonetworks.com/tag/dll-hijacking/ "DLL hijacking")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ai-enabled-malware-analysis/ "The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution")  
  ![Pictorial representation of identity abuse through trusted communication channels. Close-up view of a digital screen displaying a glitched and pixelated image of a skull-like shape.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/02_Malware_Category_1920x900-2-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 20, 2026 [#### Identity Abuse Through Trusted Communication Channels](https://unit42.paloaltonetworks.com/communication-channel-identity-risks/)

* [Authentication](https://unit42.paloaltonetworks.com/tag/authentication/ "authentication")

* [Identity theft](https://unit42.paloaltonetworks.com/tag/identity-theft/ "identity theft")

* [Malware](https://unit42.paloaltonetworks.com/tag/malware/ "malware")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/communication-channel-identity-risks/ "Identity Abuse Through Trusted Communication Channels")  
  ![Pictorial representation of Kimwolf botnet malware family. Digital screen with a warning sign reading "Malware." The background features lines of computer code and graphics, creating a sense of cybersecurity threat.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/07_Malware_Category_1920x900-3-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 11, 2026 [#### Kimwolf v7: An Evolution of the Kimwolf Botnet](https://unit42.paloaltonetworks.com/kimwolf-v7-botnet-malware/)

* [Android APK](https://unit42.paloaltonetworks.com/tag/android-apk/ "Android APK")

* [Ethereum](https://unit42.paloaltonetworks.com/tag/ethereum/ "Ethereum")

* [HTTP](https://unit42.paloaltonetworks.com/tag/http/ "HTTP")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/kimwolf-v7-botnet-malware/ "Kimwolf v7: An Evolution of the Kimwolf Botnet")  
  ![Pictorial representatiom pf Aeternum's blockchain C2. A close-up of a computer circuit board with a central microchip is depicted. Red digital data streams in the form of glowing binary numbers and arrows appear to flow in and out of the chip. The scene is illuminated with a futuristic blue and red glow.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/04_Malware_Category_1920x900-4-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 10, 2026 [#### The Permanent Threat: Analyzing Aeternum's Blockchain-Based C2 Operations and Communications](https://unit42.paloaltonetworks.com/aeternum-blockchain-c2-analysis/)

* [Aeternum](https://unit42.paloaltonetworks.com/tag/aeternum/ "Aeternum")

* [Infection chain](https://unit42.paloaltonetworks.com/tag/infection-chain/ "infection chain")

* [JSON](https://unit42.paloaltonetworks.com/tag/json/ "JSON")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/aeternum-blockchain-c2-analysis/ "The Permanent Threat: Analyzing Aeternum’s Blockchain-Based C2 Operations and Communications")  
  ![Pictorial representation of ChainDrop, a self-propagating npm worm. An artistic depiction of a digital workspace featuring an open laptop with a red virus on the screen.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/03_Malware_Category_1920x900-7-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)High Profile Threats](https://unit42.paloaltonetworks.com/category/top-cyberthreats/) August 6, 2026 [#### ChainDrop: Inside a Self-Propagating npm Worm](https://unit42.paloaltonetworks.com/chaindrop-npm-worm-analysis/)

* [Blockchain](https://unit42.paloaltonetworks.com/tag/blockchain/ "blockchain")

* [ChainDrop](https://unit42.paloaltonetworks.com/tag/chaindrop/ "ChainDrop")

* [Claude code](https://unit42.paloaltonetworks.com/tag/claude-code/ "Claude code")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/chaindrop-npm-worm-analysis/ "ChainDrop: Inside a Self-Propagating npm Worm")  
  ![Pictorial representation of Token-jacking. A person types on a laptop with multiple digital interface elements projected, including an "AI" icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/AdobeStock_1246251272-2-786x369.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 6, 2026 [#### Token Jacking: Cybercriminals Could Be Stealing Your AI Resources](https://unit42.paloaltonetworks.com/ai-token-jacking/)

* [AI API](https://unit42.paloaltonetworks.com/tag/ai-api/ "AI API")

* [AI gateway](https://unit42.paloaltonetworks.com/tag/ai-gateway/ "AI gateway")

* [API keys](https://unit42.paloaltonetworks.com/tag/api-keys/ "API keys")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ai-token-jacking/ "Token Jacking: Cybercriminals Could Be Stealing Your AI Resources")

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)  
  ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg) ![Enlarged Image]()  
  ![Newsletter](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/03/unit42-footer-subscribe-desktop.png)  
  ![UNIT 42 Small Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/palo-alto-logo-small.svg) Get updates from Unit 42

## Peace of mind comes from staying ahead of threats. Subscribe today.

Your Email

Subscribe for email updates to all Unit 42 threat research.  
By submitting this form, you agree to our [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use "Terms of Use") and acknowledge our [Privacy Statement.](https://www.paloaltonetworks.com/legal-notices/privacy "Privacy Statement")

This site is protected by reCAPTCHA and the Google [Privacy Policy](https://policies.google.com/privacy) and [Terms of Service](https://policies.google.com/terms) apply.

Invalid captcha!
Subscribe ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg) ![loader](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-loader.svg)  
{#footer} Products and Services

* [AI-Powered Network Security Platform](https://www.paloaltonetworks.com/network-security)

* [Secure AI by Design](https://www.paloaltonetworks.com/ai-security)

* [Prisma AIRS](https://www.paloaltonetworks.com/ai-security/prisma-airs)

* [AI Access Security](https://www.paloaltonetworks.com/sase/ai-access-security)

* [Cloud Delivered Security Services](https://www.paloaltonetworks.com/network-security/security-subscriptions)

* [Advanced Threat Prevention](https://www.paloaltonetworks.com/network-security/advanced-threat-prevention)

* [Advanced URL Filtering](https://www.paloaltonetworks.com/network-security/advanced-url-filtering)

* [Advanced WildFire](https://www.paloaltonetworks.com/network-security/advanced-wildfire)

* [Advanced DNS Security](https://www.paloaltonetworks.com/network-security/advanced-dns-security)

* [Enterprise Data Loss Prevention](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention)

* [Enterprise IoT Security](https://www.paloaltonetworks.com/network-security/enterprise-device-security)

* [Medical IoT Security](https://www.paloaltonetworks.com/network-security/medical-device-security)

* [Industrial OT Security](https://www.paloaltonetworks.com/network-security/ot-security-solution)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security)

* [Next-Generation Firewalls](https://www.paloaltonetworks.com/network-security/next-generation-firewall)

* [Hardware Firewalls](https://www.paloaltonetworks.com/network-security/hardware-firewall-innovations)

* [Software Firewalls](https://www.paloaltonetworks.com/network-security/software-firewalls)

* [Strata Cloud Manager](https://www.paloaltonetworks.com/network-security/strata-cloud-manager)

* [SD-WAN for NGFW](https://www.paloaltonetworks.com/network-security/sd-wan-subscription)

* [PAN-OS](https://www.paloaltonetworks.com/network-security/pan-os)

* [Panorama](https://www.paloaltonetworks.com/network-security/panorama)

* [Secure Access Service Edge](https://www.paloaltonetworks.com/sase)

* [Prisma SASE](https://www.paloaltonetworks.com/sase)

* [Application Acceleration](https://www.paloaltonetworks.com/sase/app-acceleration)

* [Autonomous Digital Experience Management](https://www.paloaltonetworks.com/sase/adem)

* [Enterprise DLP](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention)

* [Prisma Access](https://www.paloaltonetworks.com/sase/access)

* [Prisma Browser](https://www.paloaltonetworks.com/sase/prisma-browser)

* [Prisma SD-WAN](https://www.paloaltonetworks.com/sase/sd-wan)

* [Remote Browser Isolation](https://www.paloaltonetworks.com/sase/remote-browser-isolation)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security)

* [AI-Driven Security Operations Platform](https://www.paloaltonetworks.com/cortex)

* [Cloud Security](https://www.paloaltonetworks.com/cortex/cloud)

* [Cortex Cloud](https://www.paloaltonetworks.com/cortex/cloud)

* [Application Security](https://www.paloaltonetworks.com/cortex/cloud/application-security)

* [Cloud Posture Security](https://www.paloaltonetworks.com/cortex/cloud/cloud-posture-security)

* [Cloud Runtime Security](https://www.paloaltonetworks.com/cortex/cloud/runtime-security)

* [Prisma Cloud](https://www.paloaltonetworks.com/prisma/cloud)

* [AI-Driven SOC](https://www.paloaltonetworks.com/cortex)

* [Cortex XSIAM](https://www.paloaltonetworks.com/cortex/cortex-xsiam)

* [Cortex XDR](https://www.paloaltonetworks.com/cortex/cortex-xdr)

* [Cortex XSOAR](https://www.paloaltonetworks.com/cortex/cortex-xsoar)

* [Cortex Xpanse](https://www.paloaltonetworks.com/cortex/cortex-xpanse)

* [Unit 42 Managed Detection \& Response](https://www.paloaltonetworks.com/cortex/managed-detection-and-response)

* [Managed XSIAM](https://www.paloaltonetworks.com/cortex/managed-xsiam)

* [Next-Generation Identity Security](https://www.paloaltonetworks.com/idira)

* [Privileged Access Management](https://www.paloaltonetworks.com/idira/human/privileged-access-management)

* [Identity and Access Management](https://www.paloaltonetworks.com/idira/human/identity-and-access-management)

* [Endpoint Privilege Manager](https://www.paloaltonetworks.com/idira/human/endpoint-privilege-manager)

* [Identity Governance](https://www.paloaltonetworks.com/idira/human/identity-governance)

* [Workforce Password Management](https://www.paloaltonetworks.com/idira/human/workforce-password-management)

* [Agentic Identities](https://www.paloaltonetworks.com/idira/agentic)

* [Secrets Management](https://www.paloaltonetworks.com/idira/machine/secrets-management)

* [Unified Secrets Governance](https://www.paloaltonetworks.com/idira/machine/unified-secrets-governance)

* [Application Credentials Delivery](https://www.paloaltonetworks.com/idira/machine/application-credentials-delivery)

* [Vendor Privileged Access](https://www.paloaltonetworks.com/idira/human/vendor-privileged-access)

* [Threat Intel and Incident Response Services](https://www.paloaltonetworks.com/unit42)

* [Prepare for Emerging Risks](https://www.paloaltonetworks.com/unit42/frontier-ai-defense)

* [Strengthen Your Defenses](https://www.paloaltonetworks.com/unit42/strengthen-your-defenses)

* [Build Your Security Strategy](https://www.paloaltonetworks.com/unit42/build-your-security-strategy)

* [Understand the Adversary](https://www.paloaltonetworks.com/unit42/threat-intelligence)

* [Respond to a Cyber Attack](https://www.paloaltonetworks.com/unit42/respond)  
  Company

* [About Us](https://www.paloaltonetworks.com/about-us)

* [Careers](https://jobs.paloaltonetworks.com/en/)

* [Contact Us](https://www.paloaltonetworks.com/company/contact-sales)

* [Corporate Responsibility](https://www.paloaltonetworks.com/about-us/corporate-responsibility)

* [Customers](https://www.paloaltonetworks.com/customers)

* [Investor Relations](https://investors.paloaltonetworks.com/)

* [Location](https://www.paloaltonetworks.com/about-us/locations)

* [Newsroom](https://www.paloaltonetworks.com/company/newsroom)  
  Popular Links

* [Blog](https://www.paloaltonetworks.com/blog/)

* [Communities](https://www.paloaltonetworks.com/communities)

* [Content Library](https://www.paloaltonetworks.com/resources)

* [Cyberpedia](https://www.paloaltonetworks.com/cyberpedia)

* [Event Center](https://events.paloaltonetworks.com/)

* [Manage Email Preferences](https://start.paloaltonetworks.com/preference-center)

* [Products A-Z](https://www.paloaltonetworks.com/products/products-a-z)

* [Product Certifications](https://www.paloaltonetworks.com/legal-notices/trust-center/certifications)

* [Report a Vulnerability](https://www.paloaltonetworks.com/security-disclosure)

* [Sitemap](https://www.paloaltonetworks.com/sitemap)

* [Tech Docs](https://docs.paloaltonetworks.com/)

* [Unit 42](https://unit42.paloaltonetworks.com/)

* [Do Not Sell or Share My Personal Information](https://panwedd.exterro.net/portal/dsar.htm?target=panwedd)
  ![Palo Alto Networks Logo](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/pan-logo-dark.svg)

* [Privacy](https://www.paloaltonetworks.com/legal-notices/privacy)

* [Trust Center](https://www.paloaltonetworks.com/legal-notices/trust-center)

* [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use)

* [Documents](https://www.paloaltonetworks.com/legal)

Copyright © 2026 Palo Alto Networks. All Rights Reserved

* [![Youtube](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/youtube-black.svg)](https://www.youtube.com/user/paloaltonetworks)
* [![Podcast](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/icons/podcast.svg)](https://www.paloaltonetworks.com/podcasts/threat-vector)
* [![Facebook](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/facebook-black.svg)](https://www.facebook.com/PaloAltoNetworks/)
* [![LinkedIn](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/linkedin-black.svg)](https://www.linkedin.com/company/palo-alto-networks)
* [![Twitter](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/twitter-x-black.svg)](https://twitter.com/PaloAltoNtwks)
* EN  
  Select your language  
  ![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg) ![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg) ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg)

### Default Heading

Read the article ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg)  
Seekbar

![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg)  
![Volume](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-volume.svg)  
Volume
![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg)
