Close Menu
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

What's Hot

Unisoc VoLTE Video Call Exploit Chain Can Give Attackers Full Android Kernel Access

August 22, 2026

Evooo1Bot Linux Botnet Exploits Known Flaws to Turn Edge Devices Into SOCKS5 Proxies

August 22, 2026

UK Fraud Cases Hit Record High

August 21, 2026
Facebook X (Twitter) Instagram
Saturday, August 22
Facebook X (Twitter) Instagram Pinterest Vimeo
Cyberwire Daily
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice
Cyberwire Daily
Home»News»New Agent Tesla Malware Variant Boosts Evasion Capabilities
News

New Agent Tesla Malware Variant Boosts Evasion Capabilities

Team-CWDBy Team-CWDAugust 21, 2026No Comments3 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email


A new version of the notorious Agent Telsa malware contains new features designed to evade detection and steal credentials, KnowBe4 research has identified.

The cybersecurity firm provided a detailed analysis of the Agent Tesla version 4 infostealer, which was observed being dropped via a sophisticated business email compromise (BEC) lure targeting finance departments.

The malware used a novel obfuscation technique involving Unicode emoji characters embedded throughout the code body.

The final payload is configured to sweep credentials from more than 40 applications and rapidly exfiltrate them via file transfer mechanism to a single threat actor-controlled domain.

The researchers have advised security teams to update their email security rules to catch Agent Tesla before it can harvest credentials.

The New Agent Tesla Campaign

The KnowBe4 researchers observed the attempted delivery of Agent Tesla v4 in an email, which arrived as forwarded thread presenting as internal correspondence forwarded to an account’s contact.

The attackers spoofed the address of a legitimate Philippines-based commercial bank called Metropolitan Bank and Trust Company. The email thread was designed to look like an in-progress discussion the recipient has been brought into late, who was directly instructed to confirm an attached document and reply.

The malware operates via Jscript dropper, which can be launched with a simple initial open-with dialog.

The script body contains a number of Unicode emoji characters, such as hearts and water droplets, which are interleaved directly through the code. These characters obfuscate the malicious file by disrupting string-based signature matching and making the code visually noisy enough to defeat casual review.

Once launched, the script writes two files to C:UsersPublicLibraries, one of which is a misdirection, resulting in the extension passing it into DonutLoader shellcode for reflective portable executable (PE) injection.

This means the final Agent Tesla binary never touches the filesystem and cannot be detected by file-based scanners.

Agent Tesla v4 contains a number of defense evasion capabilities. Among these, it is intentionally scrambled using an obfuscator tool called “ConfuserEx” to make it nearly unreadable for anyone trying to analyze it.

The malware’s assembly also presents itself as a Python installer in its embedded metadata. In addition, it uses a standard Windows function as its first line of defense to detect if it is being watched by a debugger and stops running if it finds one to avoid being analyzed.

Before harvesting credentials, the malware creates a persistent hardware fingerprint, allowing attackers to track victims consistently across IS reinstalls or IP rotations.

Agent Tesla deploys several other persistence mechanisms, including disabling validation for all outgoing connections, ensuring the malware maintains unhindered communication with C2 infrastructure without triggering security alerts or errors.

The malware is designed to sweep credentials from various sources, including web browsers, messaging platforms and native Windows credential repositories.

Agent Tesla is also capable of intercepting keystrokes using the keylogger and clipboard tool.

All exfiltrated files include a system fingerprint header: timestamp, username, computer name, OS name, CPU, RAM, public IP and the MD5 hardware ID.

KnowBe4 noted that the credential dump lands on the attacker’s FTP server within seconds of execution, with no delayed staging.

Mitigating the Emoji-Obfuscation Tactic

The KnowBe4 blog, published on August 20, noted that the emoji-obfuscation approach in the JS dropper does not survive any YARA rule that looks for the Unicode code points used alongside JScript-specific patterns.

“A rule matching both the emoji distribution pattern and WScript.Shell or CreateObject calls will catch this family,” the researchers said.



Source

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleSAP Commerce Cloud CVE-2026-58231 Targeted in Exploitation Attempts Days After Patch
Next Article Suspected China-Nexus Actor Exploits VMware vCenter Flaw, Deploys Babuk-Derived Ransomware
Team-CWD
  • Website

Related Posts

News

Unisoc VoLTE Video Call Exploit Chain Can Give Attackers Full Android Kernel Access

August 22, 2026
News

Evooo1Bot Linux Botnet Exploits Known Flaws to Turn Edge Devices Into SOCKS5 Proxies

August 22, 2026
News

UK Fraud Cases Hit Record High

August 21, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest News

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202523 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views

All Major LLMs Exposed to Multi-Turn Manipulation, Warn Researchers

May 27, 20269 Views

Why SOC Burnout Can Be Avoided: Practical Steps

November 14, 20259 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Most Popular

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202523 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views
Our Picks

What if your romantic AI chatbot can’t keep a secret?

November 18, 2025

The hidden risks of browser extensions – and how to avoid them

September 13, 2025

It’s all fun and games until someone gets hacked

September 26, 2025

Subscribe to Updates

Get the latest news from cyberwiredaily.com

Facebook X (Twitter) Instagram Pinterest
  • Home
  • Contact
  • Privacy Policy
  • Terms of Use
  • California Consumer Privacy Act (CCPA)
© 2026 All rights reserved.

Type above and press Enter to search. Press Esc to cancel.