Researchers observed a real business email compromise (BEC) lure targeting finance teams, where attackers spoofed a legitimate bank and sent a forwarded-looking email thread to pressure recipients to open an attachment and reply. Opening the attached script would install Agent Tesla v4, an info-stealing malware designed to evade detection and quickly exfiltrate passwords and other credentials.
How the attack worked
KnowBe4 observed Agent Tesla v4 being delivered through a business email compromise style lure aimed squarely at finance departments. The email was crafted to look like a forwarded internal thread, giving the impression that the recipient had been added late to an ongoing conversation. The sender address spoofed a real bank, Metropolitan Bank and Trust Company, which added a layer of legitimacy to the message. Recipients were instructed to confirm an attached document and reply, a simple call to action designed to drive attachment execution without raising suspicion.
Once opened, the attachment launched a JScript dropper that used Unicode emoji characters to obfuscate its code. This obfuscation technique reduced the effectiveness of signature-based detection, allowing the malware to slip past some defenses. The final payload, Agent Tesla v4, is built to steal credentials from more than 40 applications and exfiltrate them rapidly, with stolen data reaching attacker infrastructure within seconds of execution and no delayed staging.
Why it succeeded
The pretext relied on urgency and familiarity. A forwarded thread suggests an existing, trusted conversation rather than a new unsolicited message, which lowers a recipient's guard. Spoofing a known bank added credibility to a request that finance staff would normally expect to see, since banking correspondence is routine in accounts payable and receivable work. The combination of a plausible internal-looking thread, a trusted sender identity, and a low-friction request to open a document and reply made the lure effective against a medium sophistication attack.
What to watch for
- Emails that arrive as a forwarded thread pulling you into a conversation you don't recognize
- Sender addresses that appear to belong to a bank or vendor but request unusual actions
- Pressure to open an attachment and reply quickly
- Attachments that trigger a simple "open with" dialog rather than a familiar document viewer
How to build resistance
Finance, accounts payable, accounts receivable, and executive assistant roles should verify unexpected forwarded threads through a known, trusted channel before opening any attachment. Requests that appear to come from banks or vendors should be confirmed using a verified phone number or vendor portal rather than replying directly to the email. Staff should be trained to treat unexpected script-based attachments with caution, since a single open-with prompt can be the first step toward infection. Because credential theft in this case happened within seconds of execution, incident response teams should encourage immediate reporting of any suspicious attachment interaction rather than waiting to confirm infection first. Techniques referenced here include T1566.001, T1656, and T1204.002.
Key findings
- KnowBe4 observed Agent Tesla v4 delivered through a BEC-style email aimed at finance departments.
- The email was crafted as a forwarded internal-looking thread and spoofed a real bank (Metropolitan Bank and Trust Company).
- Recipients were instructed to confirm an attached document and reply, driving attachment execution.
- The dropper used Unicode emoji characters to obfuscate JScript and reduce signature-based detection.
- The payload is designed to steal credentials from 40+ applications and exfiltrate them rapidly (within seconds) to attacker infrastructure.
Who’s being targeted
- Commonly targeted roles: Finance, Accounts Payable, Accounts Receivable, Executive Assistants, IT/Security (email security and incident response).
- Affected industries: Any organization with Finance/Accounts Payable functions, Banking.
- Attack channels: email.
- Impersonated: Metropolitan Bank and Trust Company (spoofed sender).
Red flags to watch for
- Unexpected forwarded thread that claims you were added late to an ongoing discussion
- Sender address is spoofed to look like a real bank
- Pressure to open an attachment and respond quickly
Frequently asked questions
What is Agent Tesla malware?
Agent Tesla v4 is an info-stealing malware designed to evade detection and quickly exfiltrate passwords and other credentials from more than 40 applications.
How did attackers get victims to open the malicious attachment?
They spoofed a real bank, Metropolitan Bank and Trust Company, and sent a forwarded-looking internal email thread instructing recipients to confirm an attached document and reply.
Why did this attack evade detection?
The dropper used Unicode emoji characters to obfuscate the JScript code, which reduced the effectiveness of signature-based detection tools.
How fast does the stolen data leave the network?
According to the findings, the credential dump reaches the attacker's FTP server within seconds of execution, with no delayed staging.
Read the video transcript
You get a forwarded email thread from Finance, copied on a bank: “Please confirm the attached document and reply.” Looks routine, right? But this is a BEC lure dropping Agent Tesla v4. It spoofs Metropolitan Bank and Trust Company, and the attachment is a JScript dropper hiding behind emoji characters to dodge detection. You double-click, hit an innocent-looking “Open with…” prompt, and in seconds Agent Tesla quietly rips passwords from dozens of apps and shoots them off to an external server, before you even finish reading the thread. If you’re suddenly pulled into a forwarded bank or finance thread with an attachment, stop. Don’t open it, call or message the requester on a known, trusted channel to confirm first.