{"id":224927,"date":"2023-04-24T09:43:57","date_gmt":"2023-04-24T13:43:57","guid":{"rendered":"https:\/\/sftarticles.wpenginepowered.com\/es\/?p=285023"},"modified":"2025-07-01T19:25:14","modified_gmt":"2025-07-02T02:25:14","slug":"this-works-agent-tesla-trojan-steals-chats-whatsapp-passwords-personal-data","status":"publish","type":"post","link":"https:\/\/cms-articles.softonic.io\/en\/this-works-agent-tesla-trojan-steals-chats-whatsapp-passwords-personal-data\/","title":{"rendered":"How Agent Tesla, the Trojan that steals WhatsApp chats, passwords and personal data works"},"content":{"rendered":"\n<p><strong>WhatsApp<\/strong> is one of the most used apps in the world. The app that years ago allowed us to stop relying on expensive SMS (they still exist) <strong>enjoys great popularity both in Spain and in Latin America<\/strong>, where <strong>Android<\/strong> phones are the majority. But WhatsApp also has a big problem: it is a magnet for cybercriminals.<\/p>\n\n\n<div class=\"sc-card-program\">\r\n  <div class=\"sc-card-program__body\">\r\n    <div class=\"sc-card-program__row clearfix\">\r\n      <div class=\"sc-card-program__col-logo\">\r\n        <img decoding=\"async\" class=\"sc-card-program__img\" alt=\"WhatsApp\" src=\"https:\/\/images.sftcdn.net\/images\/t_app-icon-s\/p\/6b5a0468-96d1-11e6-bfc6-00163ec9f5fa\/2095394417\/whatsapp-logo\" width=\"100px\" height=\"100px\">\r\n      <\/div>\r\n      <div class=\"sc-card-program__col-title\">\r\n        <span class=\"sc-card-program__title\">WhatsApp<\/span>\r\n        <a class=\"sc-card-program__button sc-card-program-internal\" href=\"https:\/\/whatsapp.en.softonic.com\/android\" target=\"_self\" rel=\"noopener noreferrer\">DOWNLOAD<\/a>\r\n      <\/div>\r\n      <div class=\"sc-card-program__col-rating\">\r\n        <svg class=\"rating-score__content\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" version=\"1.1\" x=\"0\" y=\"0\" viewbox=\"0 0 50 50\" enable-background=\"new 0 0 50 50\" xml:space=\"preserve\"><path class=\"rating-score__background rating-score--good\" fill=\"none\" stroke-width=\"6\" stroke-miterlimit=\"10\" d=\"M40 40c8.3-8.3 8.3-21.7 0-30s-21.7-8.3-30 0 -8.3 21.7 0 30\"><\/path><path class=\"rating-score__value rating-score__value--0\" fill=\"none\" stroke-width=\"6\" stroke-dashoffset=\"0\" stroke-miterlimit=\"10\" d=\"M40 40c8.3-8.3 8.3-21.7 0-30s-21.7-8.3-30 0 -8.3 21.7 0 30\"><\/path><text class=\"rating-score__number\" content=\"\" text-anchor=\"middle\" transform=\"matrix(1 0 0 1 25 31.0837)\" data-auto=\"app-user-score\"><\/text><\/svg>\r\n      <\/div>\r\n    <\/div>\r\n    <div class=\"sc-card-program__row\">\r\n      <span class=\"sc-card-program__description\"><\/span>\r\n    <\/div>\r\n    <div class=\"sc-card-program__row\">\r\n      <img decoding=\"async\" class=\"sc-card-program__bigpic\" src=\"\" onerror=\"this.style.display='none'\">\r\n    <\/div>\r\n    <a class=\"sc-card-program__link track-link sc-card-program-internal\" href=\"https:\/\/whatsapp.en.softonic.com\/android\" target=\"_self\" rel=\"noopener noreferrer\"><\/a>\r\n  <\/div>\r\n<\/div>\n\n\n\n<p>There are more and more dangers to which we are exposed by the simple fact of using WhatsApp. From scams and <a href=\"https:\/\/en.softonic.com\/articles\/this-works-new-scam-code-sent-error-whatsapp\" target=\"_blank\" rel=\"noreferrer noopener\">frauds such as the <strong>&#8220;code sent by mistake&#8221;<\/strong><\/a>, to the <strong>spread of different types of malware<\/strong>, either simply to cause damage to the device or to steal personal data and passwords.<\/p>\n\n\n\n<p>Recently, an investigation conducted by <strong><a href=\"https:\/\/www.eset.com\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">ESET<\/a><\/strong>, a cybersecurity company known for its antivirus: <strong>ESET NOD32,<\/strong> discovered the presence of a <strong>new malware<\/strong> that is affecting a multitude of people in various Latin American countries. Its purpose? To infect devices in order to steal passwords, <strong>take screenshots in apps such as WhatsApp<\/strong> and steal other data that would then be sent to cybercriminals.<\/p>\n\n\n<div class=\"sc-card-program\">\r\n  <div class=\"sc-card-program__body\">\r\n    <div class=\"sc-card-program__row clearfix\">\r\n      <div class=\"sc-card-program__col-logo\">\r\n        <img decoding=\"async\" class=\"sc-card-program__img\" alt=\"ESET NOD32 Antivirus\" src=\"https:\/\/images.sftcdn.net\/images\/t_app-icon-s\/p\/05ef1fea-96d2-11e6-91f6-00163ec9f5fa\/2275011073\/eset-nod32-antivirus-screenshot.png\" width=\"100px\" height=\"100px\">\r\n      <\/div>\r\n      <div class=\"sc-card-program__col-title\">\r\n        <span class=\"sc-card-program__title\">ESET NOD32 Antivirus<\/span>\r\n        <a class=\"sc-card-program__button sc-card-program-internal\" href=\"https:\/\/eset-nod32-antivirus.en.softonic.com\/\" target=\"_self\" rel=\"noopener noreferrer\">DOWNLOAD<\/a>\r\n      <\/div>\r\n      <div class=\"sc-card-program__col-rating\">\r\n        <svg class=\"rating-score__content\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" version=\"1.1\" x=\"0\" y=\"0\" viewbox=\"0 0 50 50\" enable-background=\"new 0 0 50 50\" xml:space=\"preserve\"><path class=\"rating-score__background rating-score--good\" fill=\"none\" stroke-width=\"6\" stroke-miterlimit=\"10\" d=\"M40 40c8.3-8.3 8.3-21.7 0-30s-21.7-8.3-30 0 -8.3 21.7 0 30\"><\/path><path class=\"rating-score__value rating-score__value--0\" fill=\"none\" stroke-width=\"6\" stroke-dashoffset=\"0\" stroke-miterlimit=\"10\" d=\"M40 40c8.3-8.3 8.3-21.7 0-30s-21.7-8.3-30 0 -8.3 21.7 0 30\"><\/path><text class=\"rating-score__number\" content=\"\" text-anchor=\"middle\" transform=\"matrix(1 0 0 1 25 31.0837)\" data-auto=\"app-user-score\"><\/text><\/svg>\r\n      <\/div>\r\n    <\/div>\r\n    <div class=\"sc-card-program__row\">\r\n      <span class=\"sc-card-program__description\"><\/span>\r\n    <\/div>\r\n    <div class=\"sc-card-program__row\">\r\n      <img decoding=\"async\" class=\"sc-card-program__bigpic\" src=\"\" onerror=\"this.style.display='none'\">\r\n    <\/div>\r\n    <a class=\"sc-card-program__link track-link sc-card-program-internal\" href=\"https:\/\/eset-nod32-antivirus.en.softonic.com\/\" target=\"_self\" rel=\"noopener noreferrer\"><\/a>\r\n  <\/div>\r\n<\/div>\n\n\n\n<p>The Trojan, known as <strong>Agent Tesla<\/strong>, spreads via phishing emails, in which the attackers <strong>impersonate real courier companies<\/strong>, even simulating the elements that make up the emails. In these, the user is told that there is a problem with a delivery and that they should <strong>download an attachment or click on a link<\/strong>. If we do so, the Trojan will infect our device.<\/p>\n\n\n\n<div class=\"wp-block-image aligncenter size-large\"><figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"713\" src=\"https:\/\/articles-img.sftcdn.net\/sft\/articles\/auto-mapping-folder\/sites\/3\/2023\/04\/correo-phishing-agent-tesla-ejemplo-1024x713-1-1024x713.jpg\" alt=\"\" class=\"wp-image-224933\" srcset=\"https:\/\/articles-img.sftcdn.net\/auto-mapping-folder\/sites\/3\/2023\/04\/correo-phishing-agent-tesla-ejemplo-1024x713-1-1024x713.jpg 1024w, https:\/\/articles-img.sftcdn.net\/auto-mapping-folder\/sites\/3\/2023\/04\/correo-phishing-agent-tesla-ejemplo-1024x713-1-300x209.jpg 300w, https:\/\/articles-img.sftcdn.net\/auto-mapping-folder\/sites\/3\/2023\/04\/correo-phishing-agent-tesla-ejemplo-1024x713-1-768x535.jpg 768w, https:\/\/articles-img.sftcdn.net\/auto-mapping-folder\/sites\/3\/2023\/04\/correo-phishing-agent-tesla-ejemplo-1024x713-1-18x12.jpg 18w, https:\/\/articles-img.sftcdn.net\/auto-mapping-folder\/sites\/3\/2023\/04\/correo-phishing-agent-tesla-ejemplo-1024x713-1-150x104.jpg 150w, https:\/\/articles-img.sftcdn.net\/auto-mapping-folder\/sites\/3\/2023\/04\/correo-phishing-agent-tesla-ejemplo-1024x713-1.jpg 1034w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure><\/div>\n\n\n\n<p>Once the Trojan is on the victim&#8217;s device, it can take <strong>screenshots of all your WhatsApp conversations<\/strong> (looking for passwords and personal data), save your keystrokes, <strong>steal browser passwords<\/strong> or even obtain information from the victim&#8217;s device.<\/p>\n\n\n<div class=\"sc-card-program\">\r\n  <div class=\"sc-card-program__body\">\r\n    <div class=\"sc-card-program__row clearfix\">\r\n      <div class=\"sc-card-program__col-logo\">\r\n        <img decoding=\"async\" class=\"sc-card-program__img\" alt=\"WhatsApp\" src=\"https:\/\/images.sftcdn.net\/images\/t_app-icon-s\/p\/6b5a0468-96d1-11e6-bfc6-00163ec9f5fa\/2095394417\/whatsapp-logo\" width=\"100px\" height=\"100px\">\r\n      <\/div>\r\n      <div class=\"sc-card-program__col-title\">\r\n        <span class=\"sc-card-program__title\">WhatsApp<\/span>\r\n        <a class=\"sc-card-program__button sc-card-program-internal\" href=\"https:\/\/whatsapp.en.softonic.com\/android\" target=\"_self\" rel=\"noopener noreferrer\">DOWNLOAD<\/a>\r\n      <\/div>\r\n      <div class=\"sc-card-program__col-rating\">\r\n        <svg class=\"rating-score__content\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" version=\"1.1\" x=\"0\" y=\"0\" viewbox=\"0 0 50 50\" enable-background=\"new 0 0 50 50\" xml:space=\"preserve\"><path class=\"rating-score__background rating-score--good\" fill=\"none\" stroke-width=\"6\" stroke-miterlimit=\"10\" d=\"M40 40c8.3-8.3 8.3-21.7 0-30s-21.7-8.3-30 0 -8.3 21.7 0 30\"><\/path><path class=\"rating-score__value rating-score__value--0\" fill=\"none\" stroke-width=\"6\" stroke-dashoffset=\"0\" stroke-miterlimit=\"10\" d=\"M40 40c8.3-8.3 8.3-21.7 0-30s-21.7-8.3-30 0 -8.3 21.7 0 30\"><\/path><text class=\"rating-score__number\" content=\"\" text-anchor=\"middle\" transform=\"matrix(1 0 0 1 25 31.0837)\" data-auto=\"app-user-score\"><\/text><\/svg>\r\n      <\/div>\r\n    <\/div>\r\n    <div class=\"sc-card-program__row\">\r\n      <span class=\"sc-card-program__description\"><\/span>\r\n    <\/div>\r\n    <div class=\"sc-card-program__row\">\r\n      <img decoding=\"async\" class=\"sc-card-program__bigpic\" src=\"\" onerror=\"this.style.display='none'\">\r\n    <\/div>\r\n    <a class=\"sc-card-program__link track-link sc-card-program-internal\" href=\"https:\/\/whatsapp.en.softonic.com\/android\" target=\"_self\" rel=\"noopener noreferrer\"><\/a>\r\n  <\/div>\r\n<\/div>\n\n\n\n<p>As always in cases of scam and phishing, to prevent your device from being infected with malware you should <strong>check the sender&#8217;s address<\/strong>. The vast majority of malicious emails present <strong>addresses with strange domains<\/strong> that either do not correspond to the company they are impersonating, or are simply a series of random numbers and letters.<\/p>\n\n\n\n<p><em>Some of the links added in the article are part of affiliate campaigns and may represent benefits for Softonic.<\/em><\/p>\n","protected":false},"excerpt":{"rendered":"<p>A new type of Trojan known as Agent Tesla is capable of taking screenshots of WhatsApp conversations or stealing passwords.<\/p>\n","protected":false},"author":9256,"featured_media":224930,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":"","wpcf-pageviews":0},"categories":[1015],"tags":[2333],"usertag":[],"vertical":[],"content-category":[],"class_list":["post-224927","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news","tag-app-subdomain-redirectionwhatsapp"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts\/224927","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/users\/9256"}],"replies":[{"embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/comments?post=224927"}],"version-history":[{"count":1,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts\/224927\/revisions"}],"predecessor-version":[{"id":320782,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts\/224927\/revisions\/320782"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/media\/224930"}],"wp:attachment":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/media?parent=224927"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/categories?post=224927"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/tags?post=224927"},{"taxonomy":"usertag","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/usertag?post=224927"},{"taxonomy":"vertical","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/vertical?post=224927"},{"taxonomy":"content-category","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/content-category?post=224927"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}