Close Menu
NCIJ Network |NCIJ Network |
    What's Hot

    Houthis claim attack on Saudi tankers in Red Sea

    July 23, 2026

    ‘Do a few big things well’: people share what they want from Andy Burnham | Andy Burnham

    July 23, 2026

    Sir Chris Bryant outlines ‘checklist’ of issues as he takes up NI secretary role

    July 23, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Houthis claim attack on Saudi tankers in Red Sea
    • ‘Do a few big things well’: people share what they want from Andy Burnham | Andy Burnham
    • Sir Chris Bryant outlines ‘checklist’ of issues as he takes up NI secretary role
    • Samsung Galaxy Z Flip 8 vs. Moto Razr Ultra: I’ve spent time with both, here’s what I prefer
    • Validating Distributed LLM Serving Benchmarks with NVIDIA srt-slurm, SLURM Recipes, Parameter Sweeps, and Pareto Analysis
    • How enterprise GenAI can amplify ransomware risk — and how to contain it
    • Senator Lummis: Ethics, other provisions in crypto Clarity Act to be further discussed
    • MIT’s new lidar chip could give self-driving cars a wider view
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network |NCIJ Network |
    Thursday, July 23
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network |NCIJ Network |
    Home»Cybersecurity

    Attackers Combo Up Evasion Tactics for BEC Phishing

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKJuly 23, 2026 Cybersecurity No Comments5 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Attackers are impersonating well-known companies to drop various remote access Trojans (RATs) and infostealers in a wide-scale phishing campaign designed for maximum evasion. The campaign highlights how threat actors continue to evolve beyond traditional executable-based attacks, using a combination of disguised font files, Lua interpreters, and in-memory execution to bypass endpoint defenses.

    Researchers at Fortinet since late March have observed the campaign, dubbed “The TFF Trap,” which uses a combination of fileless techniques and Lua-based loaders with low detection rates to deploy various malware families, including Agent Tesla, Remcos, XWorm, and Best Private Logger, according to a report published last week. The name comes from attackers’ use of a TrueType Font (.ttf) file to hide the AutoIT/Lua loader used to deliver malware.

    “In these campaigns, the dropped executable serves as an interpreter, while the core loader script is disguised as a .ttf extension,” Fortinet threat researchers Yurren Wan wrote in the report. “This disguised loader decrypts, loads, and executes the subsequent stage, which ultimately deploys the malware.”

    Related:Weak Security Continues to Fuel Russian Cyberattacks

    Attackers specifically are targeting Microsoft Windows systems with the ultimate goal of gaining control of them or using stolen data for follow-on attacks via one of the several malware types deployed in the attack. Initial engagement with victims comes through business email compromise (BEC) by using messages that use the guise of business cooperation and a company familiar to the victim to launch the attack.

    An Impersonation Attack Designed for Evasion

    Attackers have built evasion into each stage of the attack, combining several well-known techniques that are rarely seen together at scale, according to Fortinet. By abusing legitimate scripting environments, loading payloads directly into memory, and disguising malicious content as benign font files, the attackers significantly reduce opportunities for signature-based detection and static analysis and thus increase their chances at success, according to Wan.

    Still, all of this added evasion begins the same way any phishing attack starts, which is when “someone opens an email from what looks like a trusted company and acts on it,” observes Shane Barney, chief information security officer (CISO) at cybersecurity software provider Keeper Security. In this case, attackers impersonate FedEx and other shipping and logistics companies with which someone would engage without question.

    “The obfuscation layers, the Lua loader disguised as a font file, the fileless execution chain — all of it exists to survive detection after that human decision has already been made, and organizations would do well to keep that in their sightline,” he tells Dark Reading.

    Related:‘Phantom Squatting’: An Emerging AI-Driven Supply Chain Threat

    The attack chain is set in motion when a would-be victim executes an email attachment that comes in the form of a heavily obfuscated JavaScript that, when executed, establishes persistence on the victim’s system and launches a second-stage loader. Instead of dropping a conventional executable, however, the malware deploys a legitimate LuaJIT or AutoIt interpreter alongside a file disguised as .ttf that actually contains encrypted Lua bytecode.

    The interpreter then decrypts and executes the malicious code directly in memory, where it performs additional anti-analysis checks, unhooks Windows APIs that may be monitored by endpoint security tools, and reflectively loads the final payload without writing it to disk, according to Fortinet.

    In this way, obfuscation confuses static analysis, while the abuse of trusted interpreters helps blend malicious activity with legitimate processes, according to Fortinet. Later in the attack, the fake font file conceals the payload from extension-based inspection, and memory-resident execution minimizes forensic artifacts and reduces the likelihood that antivirus (AV) or even some behavior security tools will detect the malicious activity, according to Wan.

    Related:Rokarolla Android Trojan Levels Up to Full Device Control, Persistence

    Securing the Business Against Advanced Cyber Tactics

    Phishing remains a reliable attack vector for threat actors, which means organizations need to assume that their employees will likely at some point fall prey to advanced tactics like the ones The TFF Trap attackers are using. Once that happens, the key to keeping systems secure will be to lock down attack access downstream, experts say. In this case, identity and access controls can carry the weight of an attack by limiting what an attacker can access once initial access is achieved, Barney notes.

    “Limiting what any given set of credentials can reach, enforcing least privilege, requiring re-authentication for sensitive systems, and monitoring for anomalous session behavior will not stop every phishing email from landing, but they significantly constrain what an attacker can accomplish after one succeeds,” he says.

    To avoid even initial compromise by The TFF Trap, Fortinet included a comprehensive set of indicators of compromise (IoCs) for defenders to track, including URLs, Jscripts, Lua scripts, and command-and-control (C2) network addresses.

    Organizations also can try to get their employees into the habit of “interrogating urgency in email, particularly when a message arrives dressed as a routine business request from a recognizable name,” Barney adds. “Any unexpected outreach of that kind should be treated as unverified until confirmed through a separate channel,” he says.

    Attackers BEC Combo Evasion Phishing Tactics
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    How enterprise GenAI can amplify ransomware risk — and how to contain it

    Upbound says hack caused $13 million in fraudulent Acima leases

    New CISO appointments 2026 | CSO Online

    AI, security operations and the new race against time

    Fake Bahrain Alert App Deploys Android Surveillance Malware

    Swiss rail giant Stadler rejects $12.3M ransom demand after cyberattack

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Houthis claim attack on Saudi tankers in Red Sea

    July 23, 2026

    ‘Do a few big things well’: people share what they want from Andy Burnham | Andy Burnham

    July 23, 2026

    Sir Chris Bryant outlines ‘checklist’ of issues as he takes up NI secretary role

    July 23, 2026

    Samsung Galaxy Z Flip 8 vs. Moto Razr Ultra: I’ve spent time with both, here’s what I prefer

    July 23, 2026
    Latest Posts

    Trump slaps 50% tariffs on Canada and Carney vows to ‘intensify’ trade talks

    July 21, 2026

    How Two Brothers Dug for Dead Relatives: With a Shovel and a Kitchen Knife

    July 21, 2026

    Chile floods: Towns evacuated following heavy rain in Coquimbo

    July 21, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Houthis claim attack on Saudi tankers in Red Sea

    July 23, 2026

    ‘Do a few big things well’: people share what they want from Andy Burnham | Andy Burnham

    July 23, 2026

    Sir Chris Bryant outlines ‘checklist’ of issues as he takes up NI secretary role

    July 23, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.