惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

B
Blog RSS Feed
量子位
Y
Y Combinator Blog
大猫的无限游戏
大猫的无限游戏
B
Blog
U
Unit 42
C
Check Point Blog
I
InfoQ
aimingoo的专栏
aimingoo的专栏
雷峰网
雷峰网
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
博客园 - 【当耐特】
人人都是产品经理
人人都是产品经理
The Cloudflare Blog
H
Help Net Security
MongoDB | Blog
MongoDB | Blog
博客园 - Franky
H
Hackread – Cybersecurity News, Data Breaches, AI and More
J
Java Code Geeks
Microsoft Azure Blog
Microsoft Azure Blog
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
云风的 BLOG
云风的 BLOG
宝玉的分享
宝玉的分享
爱范儿
爱范儿

Todyl Blog

CyberChef: How to Decode & Decrypt Malicious Scripts (Step-by-Step Guide) Achieving Zero Trust with SASE: A Practical Roadmap for Modern Network Securityso like MSP Security Maturity Assessment: Why 79% of MSPs Are Stuck in 2025 The Rising Threat of Malicious AI: What Every Organization Needs to Know Iran Cyber Threat 2026: What SMBs and MSPs Need to Know The OneStart AI Browser Deception Cyber Insurance Requirements Based on Industry Why Third-Party Security Certification Is Your MSP's Competitive Edge Why Cyber Insurance Carriers Are Shifting to Security Assurance Iran Conflict and Cyber Risk: What North American Organizations Need to Know ‍ Why Cyber Resilience Requires Security, Compliance, and Insurance MSP Security Services: How to Position Identity Protection as Competitive Advantage Identity Security Gap Assessment: A Step-by-Step Guide for MSPs How Credential Theft Attacks Are Costing MSP Clients Millions Do I Need Cyber Insurance as a Small Business? Advanced Persistent Threats (APTs) Explained Preparing for CMMC Level 1: What Your Organization Needs to Do The Real Cost of Doing Nothing in Cybersecurity MSP Security: Build vs Buy SOC The Rise of a Cybercrime Alliance: What LockBit, Qilin, and DragonForce Mean for Business Risk Cyber Threat Recovery Strategies for MSPs What MSPs Need to Know about CIRCIA Final Rule ClickFix: The Evolution of Copy-Paste Social Engineering Akira Ransomware: Threat Assessment of a Scalable RaaS Operation The Dos and Don’ts of Applying for a Cyber Insurance Policy What Is Threat Hunting? A Practical Guide for MSPs and SMBs The Business Case for Cyber Threat Management Evaluating Free and Open Source SIEM Tools in 2026 How organizations can combat BEC Using SASE to help meet cyber insurance requirements
BECs In the Wild: When Millions of People Are Expecting t...
Nicholas Koken · 2026-01-09 · via Todyl Blog

Tax season. Black Friday. Back to school. These aren't just busy times for your business; they're prime hunting season for cybercriminals to take advantage of when executing Business Email Compromises(BECs) and similar attacks. Bad Actors know that when everyone's inbox is flooded with expected messages about the same topic, people let their guard down. And few corporate events are as universally anticipated, or as ripe for exploitation, as the annual benefits open enrollment period.

Every fall, employees across the country expect emails about health insurance, 401(k) changes, and benefits deadlines. It's the perfect cover for a phishing attack. Threat actors craft convincing messages that look like they're from HR or your benefits provider, complete with urgent deadlines and links to "update your information." One distracted click by any employee and you’re compromised.

This isn't a theoretical threat. Todyl’s MXDR team recently detected and shut down a sophisticated phishing campaign that did exactly this—exploiting the end-of-year open enrollment window to target organizations with highly credible fake benefits emails. Here's how it unfolded, how we caught it, and what it means for your security posture.

Rapid Detection and Response Saves Organizations

Response Metrics

Time to Investigation: 2 minutes, 42 seconds

Time to Containment: 15 minutes, 35 seconds

Total Case Duration: 18 minutes, 17 seconds (from creation to close)

Result: Threat neutralized in under 20 minutes from initial alert, preventing potential data exfiltration, lateral movement, and business disruption.

Event Timeline

~3:14 PM - User receives and opens a phishing email in Outlook containing a malicious link

3:14:26 PM - User clicks embedded link, which launches Microsoft Edge and redirects through a malicious domain (redirecting-v6md[.]vercel[.]app)

3:14:42 PM - (16 seconds later), malicious file "2026OpenEnrollmentBriefing.msi" downloaded (94.1 MB actual / 4.19 MB compressed)

3:14:42 PM - Todyl detects the attempted RAT (Remote Access Trojan) execution immediately

3:15:30 PM - MXDR case automatically created by Todyl platform

3:18:12 PM - Security analyst begins investigation (2 minutes, 42 seconds after case creation)

3:33:47 PM - Threat contained and case closed

Attribute Details
File Hash (SHA-1): cbe2ec3115cc0e07a00c64ff7d62e5e6c933e9a6
VirusTotal Detection: 41/72 security vendors flagged as malicious
Threat Classification: FleetDeck RAT / Tedy Trojan
C2 Infrastructure Contacted: Primary domain: agentupdate[.]fleetdeck[.]io
Multiple AWS CloudFront IPs (13.249.141.x range)
Port 443 (HTTPS) for encrypted C2 communications

Sandbox Analysis Revealed:

Upon execution in a controlled environment, the malware exhibited sophisticated evasion and social engineering tactics:

Evasion Technique #1 - File TypeManipulation:

  • Initially delivered as"2026OpenEnrollmentBriefing.msi" (Windows Installer package)
  • MSI files are often trusted by browsers and EDR solutions as legitimate software installers
  • This format bypasses many file scanning mechanisms that focus on .exe files

Evasion Technique #2 - Code Signing Abuse:

  • Digitally signed with valid certificate from "FLEETDECKINC." (Sectigo CA)
    • CertificateIssuer: Sectigo Public Code Signing CA EV R36
    • Valid from:July 19, 2024 to July 19, 2027
    • Thumbprint: CA172BACE97F7C97A6AE9E16CC9360F59E7B9CF4
  • TriggeredUAC prompt displaying "Verified publisher: ITarian LLC"
  • Leveraged trust in legitimate security/management software branding
  • Used dual-identity confusion (FleetDeck/Comodo Security Solutions/ITarian) to maximize victim trust
  • BECs In the Wild: When Millions of People Are Expecting the Same Email

EvasionTechnique #3 - Interactive C2 Setup:

  • Deployed an"ITarian Communication Client" requiring enrollment
  • Attempted to establish persistent command-and-control connection
  • Used port443 (HTTPS) to blend with legitimate traffic
  • Required victim to manually configure C2 connection parameters (host/port/token)
  • Manual enrollment step designed to evade automated sandbox detection systems

The Bottom Line: Your Best Defense is Being Prepared

Business email compromise attacks are only getting more sophisticated and even the best-trained employees can slip up. Attackers know that open enrollment season, tax deadlines, and other routine events create the perfect cover for exploiting lax security measure and inattentive users. That's why layered security and rapid detection and response capabilities are essential.

At the end of the day, it's not about being paranoid, it's about being prepared. When attackers come after your users, you want to shut them down before they can do any damage. The right combination of solutions like SASE, SIEM, endpoint protection, and 24/7 detection & response can give you the tools you need to protect your environment and dramatically reduce your risk.

Stay vigilant. Stay protected. And if you need backup, we're here to help.

About Nicholas Koken

Nick is Todyl's Director of Advanced Threat Operations. After 5 years of working with the NSA, Space Force, and US Army Cyber, Nick made the switch to bring his expertise to the private sector at Todyl. With his experiences in cyber red teams, Nick has forged that mentality into his approach for defending Todyl partners from today's advanced threats. When he's not keeping Todyl partners safe, he enjoys building and racing motorcycles.