logo

Hackers Hide Lua Loaders in Fake TTF Files to Deploy Remcos, XWorm, and Agent Tesla

ID: ebb35a93-62ab-54bb-b301-affa31c1af88

STIX ID: report--ebb35a93-62ab-54bb-b301-affa31c1af88

Feed Name: GBHackers

Threat Score
75/100

Date Published: 2026-07-17

Date Updated: 2026-07-17

Author: Mayura Kathir

...
...

This report describes a phishing campaign (tracked Oct 2025–Jun 2026) that disguises obfuscated Lua/AutoIt loaders as .ttf font files to achieve fileless, in-memory execution (LuaJIT, Donut) and deliver commodity malware (Remcos, Agent Tesla, XWorm, Snake/Best Private LOGGER); loaders use layered encryption, VEH-based on-demand decryption, anti-analysis, persistence via Scheduled Tasks, and the report includes multiple C2s, domains, URLs, and a sample hash as IOCs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.