Attackers Combo Up Evasion Tactics for BEC Phishing
Summary
Attackers are employing a combination of evasion tactics, dubbed 'The TFF Trap,' to deploy malware like Agent Tesla, Remcos, XWorm, and Best Private Logger. This technique utilizes fileless methods and loaders with low detection rates to facilitate Business Email Compromise (BEC) phishing campaigns.
IFF Assessment
FOE
This article details advanced techniques used by attackers to evade detection, which poses a direct threat to defenders.
Defender Context
Defenders need to be aware of sophisticated evasion techniques that combine fileless malware deployment with low-detection loaders. This trend indicates that attackers are actively working to bypass traditional security controls, requiring more advanced threat hunting and endpoint detection capabilities.