[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fDkXpmiuLeD51cwW0WZvpURD3In1TjVyS9m7DMGQJ5Jk":3},{"article":4,"iocs":38},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":21,"category":22,"article_tags":25},"29714542-5634-4ad7-a287-61f084da446e","Attackers Combo Up Evasion Tactics for BEC Phishing","attackers-combo-up-evasion-tactics-for-bec-phishing-a42216","\"The TFF Trap\" uses fileless techniques and loaders with low detection rates to deploy various RATs and stealers, including Agent Tesla, Remcos, XWorm, and Best Private Logger.","A new phishing campaign dubbed 'The TFF Trap' employs sophisticated evasion tactics, including fileless techniques and loaders designed to evade detection. These methods are used to deliver a variety of Remote Access Trojans (RATs) and stealers, such as Agent Tesla, Remcos, XWorm, and Best Private Logger, indicating a focus on credential harvesting and further network compromise.","Attackers use fileless techniques and low-detection loaders to deploy RATs and stealers.",null,"https:\u002F\u002Fwww.darkreading.com\u002Fendpoint-security\u002Fattackers-combo-evasion-tactics-bec-phishing","https:\u002F\u002Feu-images.contentstack.com\u002Fv3\u002Fassets\u002Fblt6d90778a997de1cd\u002Fblt2bb343e182f4af3e\u002F6a5e0b48c714ec6091e7ebc7\u002FPhishing_ronstik_Alamy.jpg?width=720&quality=80&disable=upscale","2026-07-20T18:30:22+00:00","2026-07-20T20:00:14.650019+00:00",7,[18],{"name":19,"type":20},"TFF Trap","campaign","89f78b1c-3503-45a1-9fc7-e23d2ce1c6d5",{"id":21,"icon":11,"name":23,"slug":24},"Malware","malware",[26,31,33],{"category":27},{"id":28,"icon":11,"name":29,"slug":30},"2c8f44d4-b56e-47cf-9677-04f22c9ee78d","Identity & Access","identity-access",{"category":32},{"id":21,"icon":11,"name":23,"slug":24},{"category":34},{"id":35,"icon":11,"name":36,"slug":37},"e7b231c8-5f79-4465-8d38-1ef13aea5a14","Threat Intelligence","threat-intelligence",[39,42,45,47],{"type":24,"value":40,"context":41},"Agent Tesla","Stealer malware deployed by TFF Trap campaign",{"type":24,"value":43,"context":44},"Remcos","RAT malware deployed by TFF Trap campaign",{"type":24,"value":46,"context":44},"XWorm",{"type":24,"value":48,"context":41},"Best Private Logger"]