logo

Phishing Campaign Hides Lua Loader as TrueType Font File

ID: 16fec806-b4af-5029-a7de-2cccdea6c738

STIX ID: report--16fec806-b4af-5029-a7de-2cccdea6c738

Feed Name: Infosecurity Magazine (News)

Threat Score
78/100

Date Published: 2026-07-16

Date Updated: 2026-07-16

...
...

A large-scale phishing campaign observed since March 2026 uses archives containing heavily obfuscated JavaScript disguised with a .ttf extension to drop LuaJIT or AutoIt loaders; those loaders employ fileless, in-memory techniques (Donut reflective loaders, segmented decryption via Vectored Exception Handlers, ROT/Base64 obfuscation) to install RATs and infostealers (Remcos, Agent Tesla, XWorm and a Snake Keylogger variant), with attackers using business-themed lures and scheduled tasks for persistence and credential theft.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.