The TTF Trap: A Global Campaign of a Low-Detection Lua Loader
July 16, 2026 · Fortinet Threat Research · Severity: LOW
FortiGuard Labs has uncovered a global phishing campaign using sophisticated techniques to deliver remote access trojans (RATs) and infostealers. Attackers employ obfuscated JScript and disguise malicious payloads as .ttf (TrueType Font) files, which then deploy Lua-based loaders to evade detection. The campaign targets organizations worldwide, leveraging social engineering to trick victims into executing the malicious scripts. The Lua loader exhibits low detection rates, enabling the delivery of malware like AsyncRAT and DarkComet. This campaign highlights the growing use of unconventional file types (e.g., .ttf) and scripting languages (Lua) to bypass security tools. Organizations are urged to scrutinize email attachments and enforce strict execution policies for obscure file formats to mitigate risks. The tactics underscore the need for advanced threat detection beyond traditional signature-based approaches.
FortiGuard Labs analyzes a global phishing campaign using obfuscated JScript, disguised .ttf files, and Lua loaders to deliver RATs and infostealers.
Key Takeaways
- FortiGuard Labs analyzes a global phishing campaign using obfuscated JScript, disguised.ttf files, and Lua loaders.