logo

New Agent Tesla Malware Variant Boosts Evasion Capabilities

ID: 827e4812-48dd-5c03-97a8-fb5b78e00ed1

STIX ID: report--827e4812-48dd-5c03-97a8-fb5b78e00ed1

Feed Name: Infosecurity Magazine (News)

Threat Score
75/100

Date Published: 2026-08-21

Date Updated: 2026-08-22

...
...

KnowBe4 researchers identified an active Agent Tesla v4 infostealer campaign using a sophisticated BEC lure to deliver a JScript dropper that embeds Unicode emoji to bypass signature detection; the dropper uses DonutLoader for reflective PE injection so the final Agent Tesla binary never touches disk. The malware is obfuscated (ConfuserEx), includes anti-debugging checks, creates persistent hardware fingerprints, steals credentials from over 40 applications, logs keystrokes and clipboard data, and rapidly exfiltrates harvested data to an attacker-controlled FTP server.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.