Highly localized social engineering (impersonating HR, payroll, tax, and invoicing)
Platform pivoting (moving victims from email to WhatsApp, LINE, or Microsoft Teams)
DLL sideloading
Credential phishing
Malware delivery via weaponized ZIP files
Deployment of modular backdoors (Atlas RAT)
Use of loaders (RomulusLoader, SilentRunLoader)
Use of crypter-as-a-service (Cruciferra)
Use of disposable email accounts (Outlook, Hotmail, Gmail)