At a glance: Phishing emails with obfuscated JavaScript lead to fake TTF files that serve as loaders for RATs and information stealers, employing multiple anti-analysis techniques.
Attackers abuse disguised TrueType Font files to distribute hard-to-detect malware and steal credentials as well as establish persistence on Windows systems. A campaign has been leveraging JavaScript obfuscation and Lua-based loaders since at least March 2026.
According to findings by Fortinet’s FortiGuard Labs, the campaign targets business and payment themes in phishing emails purporting to come from established companies. Victims are tricked into opening compressed archives containing obfuscated JScript. This establishes persistence and then downloads either a legitimate AutoIt executable or a LuaJIT interpreter, along with a malicious script packaged as a .ttf file.
The fake font file acts as a Lua loader that performs multiple deobfuscation steps before decrypting and executing shellcode directly in memory. The observed malware families – Agent Tesla, Remcos, XWorm, and a Snake keylogger variant named Best Private LOGGER – are equipped with advanced evasion techniques: segmented shellcode encryption, vectored exception handler-based runtime decryption, AMSI and ETW bypass, as well as API unhooking. The final payload is delivered via Donut shellcode and executed directly in memory without writing to disk.
Security experts emphasize that the campaign’s success, despite technical sophistication, originates in classic phishing tactics: a user opens an email from an apparently trustworthy source. Shane Barney, CISO at Keeper Security, warns against focusing defense solely on the technical complexity of the loader. Instead, organizations should strengthen identity and access control mechanisms – least-privilege principles, re-authentication for sensitive systems, and monitoring of anomalous session behavior significantly reduce what attackers can accomplish after successful phishing.
Jason Soroko, Senior Fellow at Sectigo, adds that security controls must not accept file extensions as proof of file type or intent. He recommends restricting Windows Script Host and AutoIt as well as employing signature-based detection systems, although these often fail against such loader sophistication.
Source: www.csoonline.com · Published July 17, 2026
Lumi AI News — AI-assisted curation in accordance with Article 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.