logo

The TTF Trap: A Global Campaign of a Low-Detection Lua Loader

ID: 36b1195c-7f57-5a1f-bb73-2fb2557f5b84

STIX ID: report--36b1195c-7f57-5a1f-bb73-2fb2557f5b84

Feed Name: Fortinet Blog

Threat Score
78/100

Date Published: 2026-07-16

Date Updated: 2026-07-16

...
...

Since March 2026, threat actors have run a large-scale phishing campaign that uses obfuscated JScript droppers to deploy AutoIt or LuaJIT loaders (often masquerading as .ttf files) which decode and execute Donut-wrapped shellcode in-memory to install RATs and keyloggers (Remcos, Agent Tesla, XWorm, Best Private LOGGER/Snake variant). The report documents multi-stage, fileless techniques, advanced anti-analysis and evasion measures, IOCs (IPs, domains, hashes), and Fortinet detection signatures and mitigation recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.