The TTF Trap: A Global Campaign of a Low-Detection Lua Loader
July 16, 2026 · Fortinet Threat Research · Severity: LOW
FortiGuard Labs has uncovered a global phishing campaign using obfuscated JScript and disguised .ttf (TrueType Font) files to deliver malware. The attackers employ Lua loaders with low detection rates to distribute remote access trojans (RATs) and infostealers, including Agent Tesla and Remcos. The campaign leverages social engineering to trick users into opening malicious attachments, which then execute a multi-stage payload delivery process. The campaign targets organizations worldwide, with a focus on sectors like finance, healthcare, and government. The use of Lua loaders and .ttf file obfuscation helps evade traditional security tools, making detection challenging. This highlights the growing sophistication of phishing attacks and the need for advanced threat detection mechanisms to combat such evolving tactics.
FortiGuard Labs analyzes a global phishing campaign using obfuscated JScript, disguised .ttf files, and Lua loaders to deliver RATs and infostealers.
Key Takeaways
- FortiGuard Labs analyzes global phishing campaign using obfuscated JScript and .ttf files.
- Lua loaders deliver RATs and infostealers in a low-detection campaign.
- Disguised .ttf files are a key vector for this persistent threat.