A new variant of the Agent Tesla malware, identified as version 4, features enhanced evasion capabilities specifically designed to steal credentials without detection. This malware utilizes innovative obfuscation techniques, including embedding Unicode emoji characters in its code, making it difficult to analyze. Delivered through a business email compromise targeting finance departments, it masquerades as internal correspondence.
Once executed, the malware collects credentials from over 40 applications and performs rapid exfiltration to a remote server. Security experts warn that existing email security protocols should be updated to counter this advanced threat.