![[Image: agent-tesla-builder.png]](https://blackhattool.com/wp-content/uploads/2025/07/agent-tesla-builder.png)
[b]Agent Tesla Builder: Key Features[/b]
The Agent Tesla Builder is a configuration tool that allows attackers to customize the malware before deployment. Key features include:
[b]1. Payload Customization[/b]
- Generates .exe, .dll, or script-based payloads.
- Supports multiple infection methods (e.g., document macros, fake installers).
- Adds itself to Windows Startup (Registry, Task Scheduler).
- Uses process hollowing (injects into legitimate processes like explorer.exe).
- Keylogging
- Clipboard theft
- Form grabbing
- Screen capture
- SMTP, FTP, Telegram, or HTTP for data exfiltration.
- Encrypted C2 (Command & Control) communication.
- Code obfuscation
- VM/Sandbox detection
- Delayed execution