Fake TTF loader used in global phishing campaign
🛡️ Fortinet's FortiGuard Labs reports a global phishing campaign using obfuscated JavaScript and a Lua-based loader disguised as a TrueType Font (.ttf) to evade detection. The attack chain delivers RATs and infostealers such as Agent Tesla, Remcos, XWorm, and a Snake Keylogger variant, employing in-memory execution and various anti-analysis techniques. Researchers noted business- and payment-themed lures, compressed archives with script loaders, and Donut shellcode to avoid writing payloads to disk. Defenders are advised to combine identity controls, application restrictions, and behavior-based detection.
