Hackers Hide Lua Loaders in Fake TTF Files to Deploy Remcos, XWorm, and Agent Tesla
ID: ebb35a93-62ab-54bb-b301-affa31c1af88
STIX ID: report--ebb35a93-62ab-54bb-b301-affa31c1af88
Feed Name: GBHackers
Threat Score
This report describes a phishing campaign (tracked Oct 2025–Jun 2026) that disguises obfuscated Lua/AutoIt loaders as .ttf font files to achieve fileless, in-memory execution (LuaJIT, Donut) and deliver commodity malware (Remcos, Agent Tesla, XWorm, Snake/Best Private LOGGER); loaders use layered encryption, VEH-based on-demand decryption, anti-analysis, persistence via Scheduled Tasks, and the report includes multiple C2s, domains, URLs, and a sample hash as IOCs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
