Anatomy of an Agent Tesla BEC Attack: From Inbox to In-Memory Infostealer
ID: 94c824f2-1e88-5d1f-8258-76c4211c0070
STIX ID: report--94c824f2-1e88-5d1f-8258-76c4211c0070
Feed Name: KnowBe4 Blog
Threat Score
This report analyzes a BEC phishing campaign delivering Agent Tesla v4 through an emoji-obfuscated JScript dropper that uses DonutLoader for reflective in-memory .NET injection; the ConfuserEx-obfuscated infostealer performs extensive anti-analysis checks, harvests credentials from browsers, email clients, Discord and Windows Vault, and exfiltrates data via FTP to ftp.melrz.com, with full IOCs and remediation recommendations provided.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
