Attackers Combo Up Evasion Tactics for BEC Phishing
ID: ddb24b4f-e3b8-5fd5-bc3f-0fb3dc87e3a2
STIX ID: report--ddb24b4f-e3b8-5fd5-bc3f-0fb3dc87e3a2
Feed Name: Dark Reading
Fortinet researchers have identified a wide-scale phishing campaign dubbed "The TFF Trap" that impersonates logistics companies to trick victims into executing obfuscated JavaScript which stages a second-stage loader. The attackers deliver a legitimate LuaJIT or AutoIt interpreter alongside a file disguised as a .ttf font that contains encrypted Lua bytecode; that loader decrypts and executes payloads in memory, unhooks Windows APIs, and reflectively loads final malware (Agent Tesla, Remcos, XWorm, Best Private Logger) to evade detection. Fortinet published IoCs (URLs, scripts, C2 addresses) and guidance emphasizing phishing defenses, identity and access controls, and employee verification of urgent requests.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
