A new Agent Tesla v4 campaign is targeting finance departments with a business email compromise-style lure that impersonates Metropolitan Bank and Trust Company and presents a forwarded, internal-looking email thread with a malicious attachment. Researchers said the attack chain is designed to look routine to recipients while delivering an infostealer that focuses on credential theft and account compromise.
After execution, the malware uses a JScript dropper with novel Unicode emoji-based obfuscation and deploys DonutLoader shellcode for reflective PE injection, allowing the final payload to run in memory without touching disk. Additional evasion features include ConfuserEx obfuscation, misleading metadata, and debugger detection, while the malware steals credentials from more than 40 applications, captures keystrokes and clipboard data, fingerprints infected hosts, and quickly exfiltrates data to an attacker-controlled FTP server; defenders were advised to hunt for emoji Unicode patterns alongside JScript indicators such as WScript.Shell and CreateObject.

Pull IOCs and campaign context straight into your stack.
2 events from the most recent confirmed update back to the earliest known activity.
On August 20, KnowBe4 published a blog post detailing the campaign's evasion methods, including ConfuserEx obfuscation, anti-debugging, hardware fingerprinting, and rapid FTP exfiltration. The post also said defenders could detect the dropper with YARA rules matching the Unicode emoji pattern alongside JScript indicators such as WScript.Shell or CreateObject.
KnowBe4 reported a new Agent Tesla v4 campaign that used a business email compromise lure impersonating Metropolitan Bank and Trust Company to target finance departments. The campaign delivered Agent Tesla through a JScript dropper using emoji-based Unicode obfuscation and in-memory execution via DonutLoader reflective PE injection.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
5 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcecybersecuritynews.com
Open sourcecryptika.com
Open sourceinfosecurity-magazine.com
Open sourceblog.knowbe4.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.