Since late March 2026, a large-scale campaign has used heavily obfuscated JScript droppers, Lua/AutoIt loaders, and fileless execution to deploy RATs and infostealers such as Agent Tesla, Remcos, XWorm, Snake Keylogger, and Best Private LOGGER. The attackers impersonate trusted companies to deliver phishing lures, then use disguised .ttf files, Donut shellcode, and layered anti-analysis techniques to gain control of infected Windows systems and exfiltrate data. #AgentTesla #Remcos #XWorm #SnakeKeylogger #BestPrivateLOGGER #LuaJIT #AutoIt
Keypoints
- The campaign has been active since late March 2026 and targets Microsoft Windows systems across organizations.
- Attackers impersonate reputable companies and use phishing emails with malicious archives or download links as the initial access vector.
- The initial JScript droppers are heavily obfuscated with junk code, string mapping, control flow flattening, and anti-tampering features.
- The malware chain drops either a disguised Lua loader or an AutoIt loader, both used to decrypt and launch later-stage payloads.
- The Lua loader uses advanced evasion methods such as decoy memory, page guards, custom ROT/Base64 decryption, XOR cycles, and VEH-based segmented execution.
- The campaign deploys multiple malware families, including Agent Tesla, Remcos, XWorm, Snake Keylogger variants, and Best Private LOGGER, enabling remote control and data theft.
- Best Private LOGGER appears to be a modified Snake Keylogger variant based on shared code structure, naming, and data collection logic.
MITRE Techniques
- [T1566.001 ] Phishing: Spearphishing Attachment â The attack begins with phishing emails carrying malicious archives to trick victims into opening the payload [âthe attacker manipulates the recipient into opening the attachmentâ]
- [T1566.002 ] Phishing: Spearphishing Link â The emails also contain links to download the malicious archive [âcontains a malicious archive or links to download oneâ]
- [T1027 ] Obfuscated Files or Information â The JScript, Lua, and AutoIt components are heavily obfuscated with junk code, encoding, and encryption [âembedded in a substantial amount of junk codeâ; âthe script employs highly complex obfuscation techniquesâ]
- [T1140 ] Deobfuscate/Decode Files or Information â The loaders reverse strings, remove delimiters, decode Base64, and apply custom ROT/XOR processing to reveal payloads [âreversing the strings, removing junk delimiters, and decoding from Base64â]
- [T1055 ] Process Injection â The AutoIt loader uses low-level ntdll.dll functions to inject and run the payload in another process [âperform process injection and execute the payloadâ]
- [T1106 ] Native API â The sample uses low-level ntdll.dll functions for execution and injection [âuses low-level ntdll.dll functionsâ]
- [T1053.005 ] Scheduled Task/Job: Scheduled Task â The JScript copies itself and establishes persistence via a Scheduled Task [âestablishes persistence via a Scheduled Taskâ]
- [T1036 ] Masquerading â The loader is disguised as a TrueType Font file and the campaign impersonates well-known companies [âmasquerading as a TrueType Font (.ttf) fileâ; âimpersonates several well-known companiesâ]
- [T1105 ] Ingress Tool Transfer â Additional stages and scripts are dropped to disk for execution [âThese dropped files may include an executable for an AutoIt interpreter or LuaJIT, along with accompanying scriptsâ]
- [T1027.001 ] Binary Padding â Junk code and filler are added to increase complexity and hide the real logic [âextensive junk codeâ; âa substantial amount of junk codeâ]
- [T1057 ] Process Discovery â The AutoIt loader creates a suspended process and prepares it as a host [âlaunch C:WindowsSyswow64colorcpl.exe as a suspended processâ]
- [T1068 ] Exploitation for Privilege Escalation â Not mentioned; no clear privilege escalation behavior is described
- [T1021.001 ] Remote Services: Remote Desktop Protocol â Not mentioned in the article
- [T1071.001 ] Application Layer Protocol: Web Protocols â The campaign uses web-delivered download links and hosted payloads [âlinks to download oneâ; âcdn.discordapp.comâ]
- [T1055.012 ] Process Injection: Process Hollowing â The campaign allocates memory in a remote process and writes decrypted shellcode before triggering execution [âallocates memory in the remote process, and writes the decrypted shellcode to the allocated regionâ]
- [T1620 ] Reflective Code Loading â Donut shellcode maps and executes the payload directly in memory without writing a normal file-based payload [âmaps and executes the payload directly in memoryâ]
- [T1218.005 ] System Binary Proxy Execution: Mshta â Not mentioned in the article
- [T1562.001 ] Impair Defenses: Disable or Modify Tools â The latest Lua loader neutralizes software and hardware breakpoints and performs API unhooking [âAPI unhooking and the neutralization of software and hardware breakpointsâ]
- [T1204.002 ] User Execution: Malicious File â Victims are induced to open malicious attachments/archives under urgency and business-lure pretexts [âcreating a sense of urgencyâ]
Indicators of Compromise
- [IP addresses ] command-and-control servers â 104.239.66.86:7004, 146.183.223.21:2404, and 107.174.34.137:443
- [Domains ] phishing/C2 infrastructure â newremupdate.duckdns.org, mail.teamengineersgroup.com, and mail.allportcargoservice.com
- [URLs ] delivery link for the malicious file â hxxps://cdn.discordapp.com/attachments/1499192125093449759/1511147377979818074/F10097782_Request-9200090_0990.PDF.JS
- [SHA-256 hashes ] malicious PDF and JScript samples â 9674da676ee226ee456d35c774715d9b58655423806f281de19dc9ef899e9532, 16f9692debe0d4e35d76b48312979e5a90a85ce066e7375269ce78f43da52769417fc4d6119dac40f276b563498a0ad3f9bf42262ec650a4463cbdbe78da388b619d2628dcf0c8e15a6febb0e562609556ca57f9f8216800ee77a39e336b8bf41c4419d687bf45bdc5474b6347e41e89459fc0f5115f0d012c46c57280b242bf81edd5e740bea0fefb5c1bbd14a671bd1daff37bf3641e34f3a1f7e93559184a1d9dd914cf623dcae4b88834744a005e5e3eae827ded1aafd23ed1d7be57b90a6700e6d2a0c285d3ebf1a55aecec63b1e42d7d581f691331c667a8920dac702996e22da4d5c0ea4b0efde0ad3eaa8fdedc60228f84fb3c56899afbb9338da2a1, and 2 more hashes
- [SHA-256 hashes ] Lua, AutoIt, Donut, and EXE samples â 05390dd0d2c84f77475c0c6aa082638e23977da591302e911cbcb071c42a9451c7159e589e29f9c866cc9983839ae9c9a1457df542a2dcd5103baf38636e08fdbbeb74e6af12536ecb6761a65ed893fbddd1b86a17cd4a61b616e5fc6106ec9ab12b743d4ecc0fe7320b6c1533e2a60bb89f94ca39a5be37143e7af27daacf048c28bc87eb4f2613117d41a716e78f62d55c19edaeea573c2c96e787da055167be4fcf88a287f783a3d199e889f9f088f77338eafe0dce70a38ade01192fb223, 1539468a21a439dd4f8d72a6c34ce503f0585281fc2e88535c3c33727bfdc7174c001e107a42d65c1b1e6092e4aa6932dbd1544d097d1a432ba27e3b4bddfcc116516e3298278719123068bf0ed808ea4e00f73c970a8a83377066b4e3c3c950, and other 2 items
- [File names ] disguised loader and payload artifacts â F10097782_Request-9200090_0990.PDF.JS and the masqueraded .ttf loader file