New Agent Tesla Malware Variant Boosts Evasion Capabilities
ID: 827e4812-48dd-5c03-97a8-fb5b78e00ed1
STIX ID: report--827e4812-48dd-5c03-97a8-fb5b78e00ed1
Feed Name: Infosecurity Magazine (News)
KnowBe4 researchers identified an active Agent Tesla v4 infostealer campaign using a sophisticated BEC lure to deliver a JScript dropper that embeds Unicode emoji to bypass signature detection; the dropper uses DonutLoader for reflective PE injection so the final Agent Tesla binary never touches disk. The malware is obfuscated (ConfuserEx), includes anti-debugging checks, creates persistent hardware fingerprints, steals credentials from over 40 applications, logs keystrokes and clipboard data, and rapidly exfiltrates harvested data to an attacker-controlled FTP server.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
