MalwareJul 20, 2026
Attackers Combo Up Evasion Tactics for BEC Phishing
Attackers use fileless techniques and low-detection loaders to deploy RATs and stealers.
Summary
A new phishing campaign dubbed 'The TFF Trap' employs sophisticated evasion tactics, including fileless techniques and loaders designed to evade detection. These methods are used to deliver a variety of Remote Access Trojans (RATs) and stealers, such as Agent Tesla, Remcos, XWorm, and Best Private Logger, indicating a focus on credential harvesting and further network compromise.
Indicators of Compromise
- malware — Agent Tesla
- malware — Remcos
- malware — XWorm
- malware — Best Private Logger
Entities
TFF Trap (campaign)