BEC Email Drops Emoji-Obfuscated Agent Tesla

Infosecurity Magazine · Medium sophistication
Last updated August 24, 2026

Researchers observed a real business email compromise (BEC) lure targeting finance teams, where attackers spoofed a legitimate bank and sent a forwarded-looking email thread to pressure recipients to open an attachment and reply. Opening the attached script would install Agent Tesla v4, an info-stealing malware designed to evade detection and quickly exfiltrate passwords and other credentials.

How the attack worked

KnowBe4 observed Agent Tesla v4 being delivered through a business email compromise style lure aimed squarely at finance departments. The email was crafted to look like a forwarded internal thread, giving the impression that the recipient had been added late to an ongoing conversation. The sender address spoofed a real bank, Metropolitan Bank and Trust Company, which added a layer of legitimacy to the message. Recipients were instructed to confirm an attached document and reply, a simple call to action designed to drive attachment execution without raising suspicion.

Once opened, the attachment launched a JScript dropper that used Unicode emoji characters to obfuscate its code. This obfuscation technique reduced the effectiveness of signature-based detection, allowing the malware to slip past some defenses. The final payload, Agent Tesla v4, is built to steal credentials from more than 40 applications and exfiltrate them rapidly, with stolen data reaching attacker infrastructure within seconds of execution and no delayed staging.

Why it succeeded

The pretext relied on urgency and familiarity. A forwarded thread suggests an existing, trusted conversation rather than a new unsolicited message, which lowers a recipient's guard. Spoofing a known bank added credibility to a request that finance staff would normally expect to see, since banking correspondence is routine in accounts payable and receivable work. The combination of a plausible internal-looking thread, a trusted sender identity, and a low-friction request to open a document and reply made the lure effective against a medium sophistication attack.

What to watch for

  • Emails that arrive as a forwarded thread pulling you into a conversation you don't recognize
  • Sender addresses that appear to belong to a bank or vendor but request unusual actions
  • Pressure to open an attachment and reply quickly
  • Attachments that trigger a simple "open with" dialog rather than a familiar document viewer

How to build resistance

Finance, accounts payable, accounts receivable, and executive assistant roles should verify unexpected forwarded threads through a known, trusted channel before opening any attachment. Requests that appear to come from banks or vendors should be confirmed using a verified phone number or vendor portal rather than replying directly to the email. Staff should be trained to treat unexpected script-based attachments with caution, since a single open-with prompt can be the first step toward infection. Because credential theft in this case happened within seconds of execution, incident response teams should encourage immediate reporting of any suspicious attachment interaction rather than waiting to confirm infection first. Techniques referenced here include T1566.001, T1656, and T1204.002.

Key findings

  • KnowBe4 observed Agent Tesla v4 delivered through a BEC-style email aimed at finance departments.
  • The email was crafted as a forwarded internal-looking thread and spoofed a real bank (Metropolitan Bank and Trust Company).
  • Recipients were instructed to confirm an attached document and reply, driving attachment execution.
  • The dropper used Unicode emoji characters to obfuscate JScript and reduce signature-based detection.
  • The payload is designed to steal credentials from 40+ applications and exfiltrate them rapidly (within seconds) to attacker infrastructure.

Who’s being targeted

  • Commonly targeted roles: Finance, Accounts Payable, Accounts Receivable, Executive Assistants, IT/Security (email security and incident response).
  • Affected industries: Any organization with Finance/Accounts Payable functions, Banking.
  • Attack channels: email.
  • Impersonated: Metropolitan Bank and Trust Company (spoofed sender).

Red flags to watch for

  • Unexpected forwarded thread that claims you were added late to an ongoing discussion
  • Sender address is spoofed to look like a real bank
  • Pressure to open an attachment and respond quickly
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

What is Agent Tesla malware?

Agent Tesla v4 is an info-stealing malware designed to evade detection and quickly exfiltrate passwords and other credentials from more than 40 applications.

How did attackers get victims to open the malicious attachment?

They spoofed a real bank, Metropolitan Bank and Trust Company, and sent a forwarded-looking internal email thread instructing recipients to confirm an attached document and reply.

Why did this attack evade detection?

The dropper used Unicode emoji characters to obfuscate the JScript code, which reduced the effectiveness of signature-based detection tools.

How fast does the stolen data leave the network?

According to the findings, the credential dump reaches the attacker's FTP server within seconds of execution, with no delayed staging.

Read the video transcript

You get a forwarded email thread from Finance, copied on a bank: “Please confirm the attached document and reply.” Looks routine, right? But this is a BEC lure dropping Agent Tesla v4. It spoofs Metropolitan Bank and Trust Company, and the attachment is a JScript dropper hiding behind emoji characters to dodge detection. You double-click, hit an innocent-looking “Open with…” prompt, and in seconds Agent Tesla quietly rips passwords from dozens of apps and shoots them off to an external server, before you even finish reading the thread. If you’re suddenly pulled into a forwarded bank or finance thread with an attachment, stop. Don’t open it, call or message the requester on a known, trusted channel to confirm first.

Similar attacks

Fake Bank of America Email Pushes Hidden ScreenConnect

Fake Bank of America Email Pushes Hidden ScreenConnect

Attackers are impersonating Bank of America in mass phishing emails to pressure people into clicking a link “to avoid account restrictions.” Mac users are led to a fake login page that steals credentials and personal/financial data, while Windows users are tricked into installing a ScreenConnect…

August 5, 2026
Tax and SSA Phish Push Cruciferra Malware Loader

Tax and SSA Phish Push Cruciferra Malware Loader

Researchers report multiple real-world email phishing campaigns that used tax and government-benefit themes to trick people into downloading malware. The campaigns used a “crypter” service called Cruciferra to hide malicious files and help malware run while avoiding detection. Targets included…

July 27, 2026
Govt-Themed Phishing Spreads Cruciferra Malware

Govt-Themed Phishing Spreads Cruciferra Malware

Proofpoint observed real phishing campaigns using government-themed lures to trick people into downloading ZIP files that install malware. The campaigns used a “crypter” service called Cruciferra to help common remote-access and data-stealing malware evade detection. Financial services, healthcare,…

July 21, 2026
Hijacked .gov.br Sites Used as Malware Lures

Hijacked .gov.br Sites Used as Malware Lures

Researchers reported an active PhantomEnigma campaign where attackers hijacked 20+ Brazilian government websites and used them as trusted stepping-stones to deliver malware. The lure used official-looking police-themed documents (sometimes with QR codes) and emails that could pass common email…

July 16, 2026
“Quote Review” Email Drops PhantomStealer

“Quote Review” Email Drops PhantomStealer

AhnLab reported a real phishing email campaign that pretends to be a sales representative asking the victim to review and revise a quote and verify product versions. The email includes a malicious compressed attachment that leads to an executable which ultimately installs PhantomStealer, an…

August 18, 2026
APT42 Lures Targets With Podcast Invites

APT42 Lures Targets With Podcast Invites

Researchers report Iranian-linked APT groups using legitimate cloud services to hide command-and-control traffic, and separately running spear-phishing campaigns. In the phishing cases, attackers used credible “podcast” or “interview invitation” themes to persuade targets to open a Windows shortcut…

August 17, 2026