logo

Attackers Combo Up Evasion Tactics for BEC Phishing

ID: ddb24b4f-e3b8-5fd5-bc3f-0fb3dc87e3a2

STIX ID: report--ddb24b4f-e3b8-5fd5-bc3f-0fb3dc87e3a2

Feed Name: Dark Reading

Threat Score
78/100

Date Published: 2026-07-20

Date Updated: 2026-07-20

Author: Elizabeth Montalbano

...
...

Fortinet researchers have identified a wide-scale phishing campaign dubbed "The TFF Trap" that impersonates logistics companies to trick victims into executing obfuscated JavaScript which stages a second-stage loader. The attackers deliver a legitimate LuaJIT or AutoIt interpreter alongside a file disguised as a .ttf font that contains encrypted Lua bytecode; that loader decrypts and executes payloads in memory, unhooks Windows APIs, and reflectively loads final malware (Agent Tesla, Remcos, XWorm, Best Private Logger) to evade detection. Fortinet published IoCs (URLs, scripts, C2 addresses) and guidance emphasizing phishing defenses, identity and access controls, and employee verification of urgent requests.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.