Phishing Campaign Hides Lua Loader as TrueType Font File
ID: 16fec806-b4af-5029-a7de-2cccdea6c738
STIX ID: report--16fec806-b4af-5029-a7de-2cccdea6c738
Feed Name: Infosecurity Magazine (News)
A large-scale phishing campaign observed since March 2026 uses archives containing heavily obfuscated JavaScript disguised with a .ttf extension to drop LuaJIT or AutoIt loaders; those loaders employ fileless, in-memory techniques (Donut reflective loaders, segmented decryption via Vectored Exception Handlers, ROT/Base64 obfuscation) to install RATs and infostealers (Remcos, Agent Tesla, XWorm and a Snake Keylogger variant), with attackers using business-themed lures and scheduled tasks for persistence and credential theft.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
