BEC Email Drops Emoji-Obfuscated Agent Tesla

Infosecurity Magazine · Medium sophistication
Last updated August 24, 2026

Researchers observed a real business email compromise (BEC) lure targeting finance teams, where attackers spoofed a legitimate bank and sent a forwarded-looking email thread to pressure recipients to open an attachment and reply. Opening the attached script would install Agent Tesla v4, an info-stealing malware designed to evade detection and quickly exfiltrate passwords and other credentials.

How the attack worked

KnowBe4 observed Agent Tesla v4 being delivered through a business email compromise style lure aimed squarely at finance departments. The email was crafted to look like a forwarded internal thread, giving the impression that the recipient had been added late to an ongoing conversation. The sender address spoofed a real bank, Metropolitan Bank and Trust Company, which added a layer of legitimacy to the message. Recipients were instructed to confirm an attached document and reply, a simple call to action designed to drive attachment execution without raising suspicion.

Once opened, the attachment launched a JScript dropper that used Unicode emoji characters to obfuscate its code. This obfuscation technique reduced the effectiveness of signature-based detection, allowing the malware to slip past some defenses. The final payload, Agent Tesla v4, is built to steal credentials from more than 40 applications and exfiltrate them rapidly, with stolen data reaching attacker infrastructure within seconds of execution and no delayed staging.

Why it succeeded

The pretext relied on urgency and familiarity. A forwarded thread suggests an existing, trusted conversation rather than a new unsolicited message, which lowers a recipient's guard. Spoofing a known bank added credibility to a request that finance staff would normally expect to see, since banking correspondence is routine in accounts payable and receivable work. The combination of a plausible internal-looking thread, a trusted sender identity, and a low-friction request to open a document and reply made the lure effective against a medium sophistication attack.

What to watch for

  • Emails that arrive as a forwarded thread pulling you into a conversation you don't recognize
  • Sender addresses that appear to belong to a bank or vendor but request unusual actions
  • Pressure to open an attachment and reply quickly
  • Attachments that trigger a simple "open with" dialog rather than a familiar document viewer

How to build resistance

Finance, accounts payable, accounts receivable, and executive assistant roles should verify unexpected forwarded threads through a known, trusted channel before opening any attachment. Requests that appear to come from banks or vendors should be confirmed using a verified phone number or vendor portal rather than replying directly to the email. Staff should be trained to treat unexpected script-based attachments with caution, since a single open-with prompt can be the first step toward infection. Because credential theft in this case happened within seconds of execution, incident response teams should encourage immediate reporting of any suspicious attachment interaction rather than waiting to confirm infection first. Techniques referenced here include T1566.001, T1656, and T1204.002.

Key findings

  • KnowBe4 observed Agent Tesla v4 delivered through a BEC-style email aimed at finance departments.
  • The email was crafted as a forwarded internal-looking thread and spoofed a real bank (Metropolitan Bank and Trust Company).
  • Recipients were instructed to confirm an attached document and reply, driving attachment execution.
  • The dropper used Unicode emoji characters to obfuscate JScript and reduce signature-based detection.
  • The payload is designed to steal credentials from 40+ applications and exfiltrate them rapidly (within seconds) to attacker infrastructure.

Who’s being targeted

  • Commonly targeted roles: Finance, Accounts Payable, Accounts Receivable, Executive Assistants, IT/Security (email security and incident response).
  • Affected industries: Any organization with Finance/Accounts Payable functions, Banking.
  • Attack channels: email.
  • Impersonated: Metropolitan Bank and Trust Company (spoofed sender).

Red flags to watch for

  • Unexpected forwarded thread that claims you were added late to an ongoing discussion
  • Sender address is spoofed to look like a real bank
  • Pressure to open an attachment and respond quickly
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

What is Agent Tesla malware?

Agent Tesla v4 is an info-stealing malware designed to evade detection and quickly exfiltrate passwords and other credentials from more than 40 applications.

How did attackers get victims to open the malicious attachment?

They spoofed a real bank, Metropolitan Bank and Trust Company, and sent a forwarded-looking internal email thread instructing recipients to confirm an attached document and reply.

Why did this attack evade detection?

The dropper used Unicode emoji characters to obfuscate the JScript code, which reduced the effectiveness of signature-based detection tools.

How fast does the stolen data leave the network?

According to the findings, the credential dump reaches the attacker's FTP server within seconds of execution, with no delayed staging.

Read the video transcript

You get a forwarded email thread from Finance, copied on a bank: “Please confirm the attached document and reply.” Looks routine, right? But this is a BEC lure dropping Agent Tesla v4. It spoofs Metropolitan Bank and Trust Company, and the attachment is a JScript dropper hiding behind emoji characters to dodge detection. You double-click, hit an innocent-looking “Open with…” prompt, and in seconds Agent Tesla quietly rips passwords from dozens of apps and shoots them off to an external server, before you even finish reading the thread. If you’re suddenly pulled into a forwarded bank or finance thread with an attachment, stop. Don’t open it, call or message the requester on a known, trusted channel to confirm first.

Similar attacks

EvilTokens Uses Device Codes to Bypass MFA

EvilTokens Uses Device Codes to Bypass MFA

Microsoft reports that the EvilTokens phishing-as-a-service platform helped criminals compromise thousands of organizations by tricking users into completing a legitimate Microsoft “device code” login. The lure drives victims to enter a short code at microsoft.com/devicelogin, which unknowingly…

September 22, 2026
Phish Emails Hide AI Prompt Injections

Phish Emails Hide AI Prompt Injections

Barracuda analyzed a real phishing campaign where one email was designed to trick both a person and the AI assistant summarizing their inbox. The messages used normal phishing lures (like password-protected attachments) while also hiding “prompt injection” instructions to make AI summaries label…

October 7, 2026
GhostCode Tricks Users Into Device-Code Login

GhostCode Tricks Users Into Device-Code Login

Researchers observed a real phishing campaign using a kit called GhostCode that abuses Microsoft’s legitimate “device code” sign-in flow to steal authentication tokens. Victims are socially engineered to open an NDA-themed HTML file and then enter a device code on Microsoft’s login page,…

September 18, 2026
M365 “Direct Send” Abused for Internal-Looking Phish

M365 “Direct Send” Abused for Internal-Looking Phish

Researchers observed a real phishing campaign that abused Microsoft 365’s Direct Send feature to make emails look like they came from the victim organization’s own domain, without compromising an employee account. The campaign was timed to mimic human sending patterns during U.S. Eastern business…

September 14, 2026
M365 Direct Send Spoofs Internal HR & Finance

M365 Direct Send Spoofs Internal HR & Finance

Researchers observed a real phishing campaign that abused Microsoft 365’s “Direct Send” feature to deliver messages that looked like they came from trusted internal addresses (HR, accounting, admin). The emails commonly used familiar business lures like invoices, payment approvals, voicemail…

September 11, 2026
Device-Code Phishing and “ClickFix” Lures Spread

Device-Code Phishing and “ClickFix” Lures Spread

This weekly recap highlights multiple real-world campaigns where attackers trick users into taking actions that grant access, without needing to steal passwords directly. Notable examples include “device code” phishing (victims are instructed to enter a short code to approve an attacker session)…

September 28, 2026