Skip to content

Security2 publishersIndependently confirmed3 min readPublished

Agent Tesla v4 hides in emoji and never hits disk: an email-rule problem, not a new-malware one

KnowBe4 says a new build of the commodity infostealer uses Unicode emoji to break string signatures and keeps its final payload off disk. The lure is a spoofed bank thread aimed at finance teams.

The Watch · Security desk

Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

What happened

  • KnowBe4 research identified a new version of Agent Tesla, version 4, an infostealer observed being dropped via a business email compromise lure targeting finance departments.
  • The email observed by KnowBe4 arrived as a forwarded thread presenting as internal correspondence forwarded to an account's contact.
  • The attackers spoofed the address of Metropolitan Bank and Trust Company, a legitimate Philippines-based commercial bank.
  • The email thread was designed to look like an in-progress discussion the recipient had been brought into late, and the recipient was directly instructed to confirm an attached document and reply.
  • The malware operates via a JScript dropper that can be launched with a simple initial open-with dialog.

Compiled by The WatchSomething wrong?How this is made

Why it matters

KnowBe4 researchers logged an attempted delivery of Agent Tesla version 4 via a business email compromise lure aimed at finance departments, and published their analysis on August 20 [1][24]. Nothing about the payload's ambitions is new; what has changed is that the delivery chain breaks string-based signature matching and file-based scanning at the same time, which leaves the mail gateway and script-level rules as the enforcement points [25].

The lure did the unglamorous work. According to KnowBe4, the message arrived as a forwarded thread presenting as internal correspondence passed to a contact of the account [21], with the address of Metropolitan Bank and Trust Company, a Philippines-based commercial bank, spoofed as the sender [22]. The thread was built to look like an in-progress discussion the recipient had been brought into late, with a direct instruction to confirm the attached document and reply [23]. That is indistinguishable from a normal accounts-payable Tuesday.

The attachment is a JScript dropper that can be launched from a simple open-with dialog [2]. Its body is interleaved with Unicode emoji characters, hearts and water droplets among them [3], which disrupt string-based signature matching and make the code visually noisy enough to defeat casual review [4]. On execution the script writes two files to C:\Users\Public\Libraries\, one of which is misdirection, and the extension is passed into DonutLoader shellcode for reflective PE injection [5]. The final Agent Tesla binary never touches the filesystem, so file-based scanners have nothing to open [6].

The payload itself is a catalogue of the usual defences: obfuscation with ConfuserEx [7], embedded metadata presenting the assembly as a Python installer [8], and a standard Windows debugger check that halts execution if it finds a debugger attached [9]. Before collection it builds a persistent hardware fingerprint so operators can track a victim across reinstalls and IP rotation [10], and it disables validation for all outgoing connections to keep C2 traffic from raising alerts or errors [11]. Collection covers browsers, messaging platforms and native Windows credential repositories [12] across more than 40 applications [13], plus keystroke and clipboard capture [14]. Every exfiltrated file carries a header with timestamp, username, computer name, OS, CPU, RAM, public IP and the MD5 hardware ID [15].

The operational detail that should shape your playbook is the timing. KnowBe4 reports the credential dump lands on the attacker's FTP server within seconds of execution, with no delayed staging [16], sent to a single threat actor-controlled domain [17]. There is effectively no dwell window between click and credential loss, so post-execution containment is a rotation exercise, not an interception one [26].

The mitigation KnowBe4 proposes is correspondingly cheap. The firm says the emoji obfuscation does not survive any YARA rule looking for the Unicode code points used alongside JScript-specific patterns [18], and states that "a rule matching both the emoji distribution pattern and WScript.Shell or CreateObject calls will catch this family" [19]. Their advice to defenders is to update email security rules rather than wait for the endpoint to catch it [20].

Two things worth checking this week. First, whether your mail filtering inspects script attachments at the code-point level at all, since that is the specific gap the technique exploits [18]. Second, whether finance staff have any procedure that treats being forwarded into a live thread late, with an instruction to confirm an attachment, as a reason to verify out of band [23].

Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories