Back to Feed
MalwareJul 20, 2026

Attackers Combo Up Evasion Tactics for BEC Phishing

Attackers use fileless techniques and low-detection loaders to deploy RATs and stealers.

Summary

A new phishing campaign dubbed 'The TFF Trap' employs sophisticated evasion tactics, including fileless techniques and loaders designed to evade detection. These methods are used to deliver a variety of Remote Access Trojans (RATs) and stealers, such as Agent Tesla, Remcos, XWorm, and Best Private Logger, indicating a focus on credential harvesting and further network compromise.

Indicators of Compromise

  • malware — Agent Tesla
  • malware — Remcos
  • malware — XWorm
  • malware — Best Private Logger

Entities

TFF Trap (campaign)