Agent Tesla v4 Hidden Behind Unicode-Emoji-Obfuscated JScript Evades Detection in BEC Campaign Targeting Finance Teams — Threadlinqs Intelligence
As of 2026-08-22, Agent Tesla v4 Hidden Behind Unicode-Emoji-Obfuscated JScript Evades Detection in BEC Campaign Targeting Finance Teams is a high-severity malware threat, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 17 indicators of compromise.
Threat ID: TL-2026-2108 · Severity: HIGH · Status: ACTIVE · Category: MALWARE
An active Agent Tesla v4 business email compromise campaign impersonates Metropolitan Bank and Trust Company (Philippines) to deliver a 6.94 MB JScript attachment whose code body is saturated with
KnowBe4 Threat Labs documented an in-the-wild Agent Tesla v4 campaign that pairs a convincing wire-transfer BEC lure with a fileless, multi-stage execution chain. The initial vector is a forwarded-thread phishing email spoofing Metropolitan Bank and Trust Company, a Philippine bank, urging the recipient to confirm an attached 'SWIFT Payment Maker 103 - 10.06.26.JS' file (SHA-256 615f9ecc51ccce0de6e88dcff70662f77965214bf5ad0cc7e07bc4fae72c40d0, 6.94 MB).
The attachment is a JScript dropper whose entire obfuscation layer consists of Unicode emoji characters (hearts, water droplets) interleaved throughout the functional code. Windows Script Host's JScript interpreter parses past these characters as noise while executing the underlying logic untouched, defeating casual analyst review and string-based signature matching. On execution, the dropper writes two files to C:\Users\Public\Libraries\: wabmmxofrrdsjlsx.exe, a 32-bit .NET loader, and wabmmxofrrdsjlsx.ttf, an encoded Agent Tesla payload blob disguised as a font file. The loader reads the .ttf as raw bytes and passes them to DonutLoader shellcode, which performs reflective PE injection so the final Agent Tesla binary never touches disk.
Before harvesting begins, the payload runs a five-stage anti-analysis gauntlet: GetModuleHandle checks for SbieDll.dll (Sandboxie), snxhk.dll (Avast sandbox hook), cmdvrt32.dll (Comodo Containment), SxIn.dll (360 Total Security), and Sf2.dll (AVG/Avast); CheckRemoteDebuggerPresent debugger detection; Thread.Sleep-based VM timing checks; WMI queries against Win32_ComputerSystem for VirtualBox/VMware manufacturer strings; and a hosting-provider lookup against the legitimate ip-api.com service to detect cloud/VPS sandboxes. The payload itself is a ConfuserEx-obfuscated .NET 4.0 binary whose assembly metadata falsely declares AssemblyProduct 'Python 3.11.3 (64-bit)' and AssemblyCompany 'Python Software Foundation' despite being a 32-bit x86 .NET executable.
Once environment checks pass, Agent Tesla v4 immediately runs 21+ credential-harvesting modules covering 27 Chromium-based browsers (including Chrome, Edge, Brave, Opera, Vivaldi, Yandex) and 13 Mozilla-based browsers (Firefox, Thunderbird, SeaMonkey, Waterfox, Pale Moon), decrypting Chrome 80+ credential stores via Local State master-key retrieval and AES-GCM decryption of v10/v11 blobs, and falling back to CryptUnprotectData for legacy Chrome. It also pulls Outlook (versions 11.0-16.0) credentials from the registry, Foxmail passwords, Thunderbird contacts, Windows Credential Manager/Vault entries, and Discord LevelDB-stored OAuth2 session tokens for account takeover. Keylogging and clipboard capture run continuously; a screen-capture module is present but was disabled in the analyzed sample. The malware also derives a hardware fingerprint from WMI-sourced motherboard serial, processor ID, and MAC address to let the operator track individual victims.
For persistence, the malware copies itself to %APPDATA%\eCXCES\eCXCES.exe and registers HKCU\Software\Microsoft\Windows\CurrentVersion\Run\eCXCES. Stolen credentials, keylogs, screenshots, and contact lists are exfiltrated within seconds of collection via .NET FtpWebRequest STOR commands to a single hardcoded FTP server, ftp.melrz.com (162.0.209.89, TCP ports 21 and 12038), authenticating with embedded credentials info@melrz.com / Newmoney2023.. File naming follows a fixed convention: PW_{user}/{host}_{datetime}.html for credentials, KL_ for keylogs, SC_ for screenshots, and Contacts_ for harvested contact lists.
Target sectors: finance, banking
Target regions: philippines, Global
Timeline
- Agent Tesla is first documented as a commodity .NET-based keylogger and information-stealer sold as malware-as-a-service; it later evolves into the v4 lineage used in this campaign.
- KnowBe4 researchers observe a BEC email spoofing Metropolitan Bank and Trust Company (Philippines) delivering a 6.94 MB JScript attachment, 'SWIFT Payment Maker 103 - 10.06.26.JS', to finance-team targets.
- Windows Script Host executes the Unicode-emoji-obfuscated JScript dropper (SHA-256 615f9ecc51ccce0de6e88dcff70662f77965214bf5ad0cc7e07bc4fae72c40d0), which writes wabmmxofrrdsjlsx.exe and wabmmxofrrdsjlsx.ttf to C:\Users\Public\Libraries\.
- The dropped loader runs a five-stage sandbox/AV detection gauntlet (SbieDll.dll, snxhk.dll, cmdvrt32.dll, SxIn.dll, Sf2.dll module checks), CheckRemoteDebuggerPresent, VM timing checks, WMI hardware queries, and an ip-api.com hosting-provider lookup before proceeding.
- DonutLoader shellcode decodes the wabmmxofrrdsjlsx.ttf blob and reflectively injects the ConfuserEx-obfuscated, Python-metadata-spoofed .NET 4.0 Agent Tesla v4 payload directly into memory, so the final binary never touches disk.
- Agent Tesla v4 immediately harvests stored credentials from 27 Chromium and 13 Mozilla browsers, Outlook, Foxmail, Thunderbird, Discord tokens, and Windows Credential Manager, alongside keylogging and clipboard capture.
- The malware copies itself to %APPDATA%\eCXCES\eCXCES.exe and registers the HKCU\Software\Microsoft\Windows\CurrentVersion\Run\eCXCES autorun key to survive reboot.
- Stolen credentials, keylogs, screenshots, and contacts are uploaded within seconds via FtpWebRequest STOR commands to ftp.melrz.com (162.0.209.89), authenticating with the hardcoded info@melrz.com FTP account.
- KnowBe4 Threat Labs publishes 'Anatomy of an Agent Tesla BEC Attack: From Inbox to In-Memory Infostealer,' the primary technical analysis of the campaign.
- Cyber Security News, GBHackers, and Infosecurity Magazine independently report on the KnowBe4 findings, broadening awareness of the Unicode-emoji JScript evasion technique.
Detections & IOCs
As of 2026-09-06, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 17 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
Community OSINT corroboration
3 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.
MALWARE, HIGH, threat intelligence, cybersecurity, T1566.001, T1204.002, T1059.007, T1547.001, T1027.002, T1140, T1620, T1497.001, T1622, T1082