← Back to Feed

The TTF Trap: A Global Campaign of a Low-Detection Lua Loader

July 16, 2026 · Fortinet Threat Research · Severity: LOW

FortiGuard Labs analyzed a global phishing campaign that uses obfuscated JScript and disguised .ttf files to deploy a Lua loader. This loader delivers remote access trojans and infostealers while maintaining a low detection rate. The research highlights the technical details of this multi-stage attack chain.

FortiGuard Labs analyzes a global phishing campaign using obfuscated JScript, disguised .ttf files, and Lua loaders to deliver RATs and infostealers.

      

Key Takeaways

  • Global phishing campaign uses obfuscated JScript and disguised .ttf files to evade detection.
  • Lua loaders deliver remote access trojans and infostealers to compromised systems.
  • FortiGuard Labs provides technical analysis of this low-detection threat chain.
☕ Buy a Coffee