← Back to Feed
The TTF Trap: A Global Campaign of a Low-Detection Lua Loader
July 16, 2026 · Fortinet Threat Research · Severity: LOW
FortiGuard Labs analyzed a global phishing campaign that uses obfuscated JScript and disguised .ttf files to deploy a Lua loader. This loader delivers remote access trojans and infostealers while maintaining a low detection rate. The research highlights the technical details of this multi-stage attack chain.
FortiGuard Labs analyzes a global phishing campaign using obfuscated JScript, disguised .ttf files, and Lua loaders to deliver RATs and infostealers.
Key Takeaways
- Global phishing campaign uses obfuscated JScript and disguised .ttf files to evade detection.
- Lua loaders deliver remote access trojans and infostealers to compromised systems.
- FortiGuard Labs provides technical analysis of this low-detection threat chain.