The TTF Trap: A Global Campaign of a Low-Detection Lua Loader
ID: 36b1195c-7f57-5a1f-bb73-2fb2557f5b84
STIX ID: report--36b1195c-7f57-5a1f-bb73-2fb2557f5b84
Feed Name: Fortinet Blog
Since March 2026, threat actors have run a large-scale phishing campaign that uses obfuscated JScript droppers to deploy AutoIt or LuaJIT loaders (often masquerading as .ttf files) which decode and execute Donut-wrapped shellcode in-memory to install RATs and keyloggers (Remcos, Agent Tesla, XWorm, Best Private LOGGER/Snake variant). The report documents multi-stage, fileless techniques, advanced anti-analysis and evasion measures, IOCs (IPs, domains, hashes), and Fortinet detection signatures and mitigation recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
