The TTF Trap: A Global Campaign of a Low-Detection Lua Loader

The TTF Trap: A Global Campaign of a Low-Detection Lua Loader
Since late March 2026, a large-scale campaign has used heavily obfuscated JScript droppers, Lua/AutoIt loaders, and fileless execution to deploy RATs and infostealers such as Agent Tesla, Remcos, XWorm, Snake Keylogger, and Best Private LOGGER. The attackers impersonate trusted companies to deliver phishing lures, then use disguised .ttf files, Donut shellcode, and layered anti-analysis techniques to gain control of infected Windows systems and exfiltrate data. #AgentTesla #Remcos #XWorm #SnakeKeylogger #BestPrivateLOGGER #LuaJIT #AutoIt

Keypoints

  • The campaign has been active since late March 2026 and targets Microsoft Windows systems across organizations.
  • Attackers impersonate reputable companies and use phishing emails with malicious archives or download links as the initial access vector.
  • The initial JScript droppers are heavily obfuscated with junk code, string mapping, control flow flattening, and anti-tampering features.
  • The malware chain drops either a disguised Lua loader or an AutoIt loader, both used to decrypt and launch later-stage payloads.
  • The Lua loader uses advanced evasion methods such as decoy memory, page guards, custom ROT/Base64 decryption, XOR cycles, and VEH-based segmented execution.
  • The campaign deploys multiple malware families, including Agent Tesla, Remcos, XWorm, Snake Keylogger variants, and Best Private LOGGER, enabling remote control and data theft.
  • Best Private LOGGER appears to be a modified Snake Keylogger variant based on shared code structure, naming, and data collection logic.

MITRE Techniques

  • [T1566.001 ] Phishing: Spearphishing Attachment – The attack begins with phishing emails carrying malicious archives to trick victims into opening the payload [‘the attacker manipulates the recipient into opening the attachment’]
  • [T1566.002 ] Phishing: Spearphishing Link – The emails also contain links to download the malicious archive [‘contains a malicious archive or links to download one’]
  • [T1027 ] Obfuscated Files or Information – The JScript, Lua, and AutoIt components are heavily obfuscated with junk code, encoding, and encryption [’embedded in a substantial amount of junk code’; ‘the script employs highly complex obfuscation techniques’]
  • [T1140 ] Deobfuscate/Decode Files or Information – The loaders reverse strings, remove delimiters, decode Base64, and apply custom ROT/XOR processing to reveal payloads [‘reversing the strings, removing junk delimiters, and decoding from Base64’]
  • [T1055 ] Process Injection – The AutoIt loader uses low-level ntdll.dll functions to inject and run the payload in another process [‘perform process injection and execute the payload’]
  • [T1106 ] Native API – The sample uses low-level ntdll.dll functions for execution and injection [‘uses low-level ntdll.dll functions’]
  • [T1053.005 ] Scheduled Task/Job: Scheduled Task – The JScript copies itself and establishes persistence via a Scheduled Task [‘establishes persistence via a Scheduled Task’]
  • [T1036 ] Masquerading – The loader is disguised as a TrueType Font file and the campaign impersonates well-known companies [‘masquerading as a TrueType Font (.ttf) file’; ‘impersonates several well-known companies’]
  • [T1105 ] Ingress Tool Transfer – Additional stages and scripts are dropped to disk for execution [‘These dropped files may include an executable for an AutoIt interpreter or LuaJIT, along with accompanying scripts’]
  • [T1027.001 ] Binary Padding – Junk code and filler are added to increase complexity and hide the real logic [‘extensive junk code’; ‘a substantial amount of junk code’]
  • [T1057 ] Process Discovery – The AutoIt loader creates a suspended process and prepares it as a host [‘launch C:WindowsSyswow64colorcpl.exe as a suspended process’]
  • [T1068 ] Exploitation for Privilege Escalation – Not mentioned; no clear privilege escalation behavior is described
  • [T1021.001 ] Remote Services: Remote Desktop Protocol – Not mentioned in the article
  • [T1071.001 ] Application Layer Protocol: Web Protocols – The campaign uses web-delivered download links and hosted payloads [‘links to download one’; ‘cdn.discordapp.com’]
  • [T1055.012 ] Process Injection: Process Hollowing – The campaign allocates memory in a remote process and writes decrypted shellcode before triggering execution [‘allocates memory in the remote process, and writes the decrypted shellcode to the allocated region’]
  • [T1620 ] Reflective Code Loading – Donut shellcode maps and executes the payload directly in memory without writing a normal file-based payload [‘maps and executes the payload directly in memory’]
  • [T1218.005 ] System Binary Proxy Execution: Mshta – Not mentioned in the article
  • [T1562.001 ] Impair Defenses: Disable or Modify Tools – The latest Lua loader neutralizes software and hardware breakpoints and performs API unhooking [‘API unhooking and the neutralization of software and hardware breakpoints’]
  • [T1204.002 ] User Execution: Malicious File – Victims are induced to open malicious attachments/archives under urgency and business-lure pretexts [‘creating a sense of urgency’]

Indicators of Compromise

  • [IP addresses ] command-and-control servers – 104.239.66.86:7004, 146.183.223.21:2404, and 107.174.34.137:443
  • [Domains ] phishing/C2 infrastructure – newremupdate.duckdns.org, mail.teamengineersgroup.com, and mail.allportcargoservice.com
  • [URLs ] delivery link for the malicious file – hxxps://cdn.discordapp.com/attachments/1499192125093449759/1511147377979818074/F10097782_Request-9200090_0990.PDF.JS
  • [SHA-256 hashes ] malicious PDF and JScript samples – 9674da676ee226ee456d35c774715d9b58655423806f281de19dc9ef899e9532, 16f9692debe0d4e35d76b48312979e5a90a85ce066e7375269ce78f43da52769417fc4d6119dac40f276b563498a0ad3f9bf42262ec650a4463cbdbe78da388b619d2628dcf0c8e15a6febb0e562609556ca57f9f8216800ee77a39e336b8bf41c4419d687bf45bdc5474b6347e41e89459fc0f5115f0d012c46c57280b242bf81edd5e740bea0fefb5c1bbd14a671bd1daff37bf3641e34f3a1f7e93559184a1d9dd914cf623dcae4b88834744a005e5e3eae827ded1aafd23ed1d7be57b90a6700e6d2a0c285d3ebf1a55aecec63b1e42d7d581f691331c667a8920dac702996e22da4d5c0ea4b0efde0ad3eaa8fdedc60228f84fb3c56899afbb9338da2a1, and 2 more hashes
  • [SHA-256 hashes ] Lua, AutoIt, Donut, and EXE samples – 05390dd0d2c84f77475c0c6aa082638e23977da591302e911cbcb071c42a9451c7159e589e29f9c866cc9983839ae9c9a1457df542a2dcd5103baf38636e08fdbbeb74e6af12536ecb6761a65ed893fbddd1b86a17cd4a61b616e5fc6106ec9ab12b743d4ecc0fe7320b6c1533e2a60bb89f94ca39a5be37143e7af27daacf048c28bc87eb4f2613117d41a716e78f62d55c19edaeea573c2c96e787da055167be4fcf88a287f783a3d199e889f9f088f77338eafe0dce70a38ade01192fb223, 1539468a21a439dd4f8d72a6c34ce503f0585281fc2e88535c3c33727bfdc7174c001e107a42d65c1b1e6092e4aa6932dbd1544d097d1a432ba27e3b4bddfcc116516e3298278719123068bf0ed808ea4e00f73c970a8a83377066b4e3c3c950, and other 2 items
  • [File names ] disguised loader and payload artifacts – F10097782_Request-9200090_0990.PDF.JS and the masqueraded .ttf loader file


Read more: https://feeds.fortinet.com/~/960560447/0/fortinet/blog/threat-research~The-TTF-Trap-A-Global-Campaign-of-a-LowDetection-Lua-Loader