Security1 distinct publisher3 min readUpdated
KnowBe4 says a new build of the commodity infostealer uses Unicode emoji to break string signatures and keeps its final payload off disk. The lure is a spoofed bank thread aimed at finance teams.
The Watch · Security desk
Compiled by The WatchSomething wrong?How this is made
KnowBe4 researchers logged an attempted delivery of Agent Tesla version 4 via a business email compromise lure aimed at finance departments, and published their analysis on August 20 [1][25]. Nothing about the payload's ambitions is new; what has changed is that the delivery chain breaks string-based signature matching and file-based scanning at the same time, which leaves the mail gateway and script-level rules as the enforcement points [26].
The lure did the unglamorous work. According to KnowBe4, the message arrived as a forwarded thread presenting as internal correspondence passed to a contact of the account [3], with the address of Metropolitan Bank and Trust Company, a Philippines-based commercial bank, spoofed as the sender [4]. The thread was built to look like an in-progress discussion the recipient had been brought into late, with a direct instruction to confirm the attached document and reply [5]. That is indistinguishable from a normal accounts-payable Tuesday.
The attachment is a JScript dropper that can be launched from a simple open-with dialog [6]. Its body is interleaved with Unicode emoji characters, hearts and water droplets among them [7], which disrupt string-based signature matching and make the code visually noisy enough to defeat casual review [8]. On execution the script writes two files to C:\Users\Public\Libraries\, one of which is misdirection, and the extension is passed into DonutLoader shellcode for reflective PE injection [9]. The final Agent Tesla binary never touches the filesystem, so file-based scanners have nothing to open [10].
The payload itself is a catalogue of the usual defences: obfuscation with ConfuserEx [11], embedded metadata presenting the assembly as a Python installer [12], and a standard Windows debugger check that halts execution if it finds a debugger attached [13]. Before collection it builds a persistent hardware fingerprint so operators can track a victim across reinstalls and IP rotation [14], and it disables validation for all outgoing connections to keep C2 traffic from raising alerts or errors [15]. Collection covers browsers, messaging platforms and native Windows credential repositories [16] across more than 40 applications [17], plus keystroke and clipboard capture [18]. Every exfiltrated file carries a header with timestamp, username, computer name, OS, CPU, RAM, public IP and the MD5 hardware ID [19].
The operational detail that should shape your playbook is the timing. KnowBe4 reports the credential dump lands on the attacker's FTP server within seconds of execution, with no delayed staging [20], sent to a single threat actor-controlled domain [21]. There is effectively no dwell window between click and credential loss, so post-execution containment is a rotation exercise, not an interception one [27].
The mitigation KnowBe4 proposes is correspondingly cheap. The firm says the emoji obfuscation does not survive any YARA rule looking for the Unicode code points used alongside JScript-specific patterns [22], and states that "a rule matching both the emoji distribution pattern and WScript.Shell or CreateObject calls will catch this family" [23]. Their advice to defenders is to update email security rules rather than wait for the endpoint to catch it [24].
Two things worth checking this week. First, whether your mail filtering inspects script attachments at the code-point level at all, since that is the specific gap the technique exploits [22]. Second, whether finance staff have any procedure that treats being forwarded into a live thread late, with an instruction to confirm an attachment, as a reason to verify out of band [5].
Follow any of these and your For You feed starts watching them — no settings page required.
Ranked by verification strength, evidence, and original report placement.
KnowBe4 research identified a new version of Agent Tesla, version 4, an infostealer observed being dropped via a business email compromise lure targeting finance departments.
The KnowBe4 blog containing the analysis was published on August 20.
The email observed by KnowBe4 arrived as a forwarded thread presenting as internal correspondence forwarded to an account's contact.
The attackers spoofed the address of Metropolitan Bank and Trust Company, a legitimate Philippines-based commercial bank.
The email thread was designed to look like an in-progress discussion the recipient had been brought into late, and the recipient was directly instructed to confirm an attached document and reply.
The malware operates via a JScript dropper that can be launched with a simple initial open-with dialog.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Detailed but single-sourced vendor analysis, no IoCs
The technical account is specific and internally coherent — named tooling (ConfuserEx, DonutLoader), a concrete drop path, an exfiltration header schema and a proposed YARA construction — which is more than assertion. But every element traces to one vendor blog relayed by one trade outlet, with no hashes, no C2 or FTP indicators, no sample availability and no independent corroboration, so nothing is externally verifiable.
One observed delivery attempt, no prevalence data
The supplied reporting documents a single observed attempted delivery against a finance recipient. There is no victim count, no volume of messages, no sector or regional spread and no confirmation of successful compromise, so observed real-world deployment of this specific build is minimal on the record available.
Evasion framing overstated by the vendor's own mitigation
The framing is 'boosted evasion capabilities' on a fileless, emoji-obfuscated stealer, yet the same analysis concludes the obfuscation does not survive a single YARA rule pairing emoji code points with WScript.Shell or CreateObject calls, and the underlying family is long-established commodity malware. Combined with one observed delivery attempt and no IoCs or victim data, the novelty and threat framing runs ahead of what the evidence and observed spread support.
Vendor research ending in a buy-adjacent recommendation
The analysis originates with a commercial security vendor whose business includes email security and phishing/awareness training, and the write-up closes by advising security teams to update their email security rules. That alignment between finding and product category is a visible incentive, and the relaying outlet carries the recommendation without disclosing it.
Coherent but unverifiable and uncorroborated
Confidence is limited by structure rather than by contradiction: one publisher, one vendor origin, no dissenting or confirming account, and no indicators that would let a third party test the claims. The technical narrative is plausible and self-consistent, and the derived operational implications follow directly from the reported timing and fileless delivery, which keeps confidence mid-range rather than low.
build
GitLab bundles a zero-click GraphQL flaw with a CSRF bug, and only one needs a victim1 distinct publisher
security
Akrites switches on in September with 20-odd members and a one-to-10 engineer donation band1 distinct publisher
build
ShieldBreak: a Defender-to-SYSTEM PoC that your last patch cycle did not stop1 distinct publisher
product
After Arup, a face on a video call is not a credential1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 21, 2026