Threat reportMalwareTL-2026-2402

The TTF Trap — Global Campaign Using Low-Detection Lua Loader Disguised as TrueType Font Files to Deploy RATs and Infostealers

highACTIVE

The TTF Trap (TL-2026-2402), also tracked as TTF Trap, is a high-severity malware campaign, first published 2026-09-08. It has no confirmed attribution, affects Microsoft Windows, maps to 21 MITRE ATT&CK techniques (T1027.002, T1027.007, T1027.013), and is covered by 9 detection rules and 23 indicators of compromise.

Severity
HIGHAssessed severity
CVEs
0None referenced
Techniques
21MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
23Indicators of compromise

Key facts for TL-2026-2402

Threat ID
TL-2026-2402
Also known as
TTF Trap
Severity
HIGH
Status
ACTIVE
Category
MALWARE
First published
Last reviewed
Attribution confidence
LOW
Motivation
FINANCIAL
Target sectors
finance, manufacturing, logistics, technology, health
Target regions
North America, Europe, Asia Pacific, Middle East
Detection rules
9
Indicators of compromise
23

Malware and tooling in The TTF Trap

Malware and tooling: 404 Keylogger, Agent Tesla, Formbook, Rakhni, XWorm, Remcos

How The TTF Trap works

Since late March 2026, a large-scale global phishing campaign delivers fileless Lua-based loaders disguised as .ttf (TrueType Font) files. The multi-stage infection chain progresses from phishing email to obfuscated JScript dropper, then LuaJIT or AutoIt loader executing Donut shellcode via reflective loading, ultimately deploying Agent Tesla, Remcos, XWorm, Snake Keylogger (Best Private LOGGER variant), and Formbook. The Lua loader has evolved from a simpler October 2025 variant using CreateRemoteThread to a sophisticated June 2026 version employing Vectored Exception Handler-based segmented encryption, API unhooking, AMSI/ETW bypass, and breakpoint neutralization, achieving very low detection rates.

The TTF Trap campaign represents a sophisticated, multi-stage malware delivery operation that has remained largely undetected since its inception due to novel evasion techniques and a carefully layered infection chain. First observed by FortiGuard Labs via samples dating to October 2025, the campaign escalated significantly in late March 2026 and continued evolving through June 2026.

Initial Access & Delivery: Attackers send phishing emails impersonating well-known companies using business cooperation and payment-related lures. These emails contain compressed archives (ZIP/RAR) or download links pointing to malicious payloads hosted on legitimate services. One confirmed staging URL abuses Discord's CDN infrastructure: hxxps://cdn.discordapp.com/attachments/1499192125093449759/1511147377979818074/F10097782_Request-9200090_0990.PDF.JS.

Stage 1 — JScript Dropper: The archive contains an obfuscated JScript file employing heavy anti-analysis: string array mapping (critical strings accessed by index), control flow flattening (complex branching to confuse analysis), and anti-tampering integrity checks. ActiveX object names and output file paths use junk delimiters removed at runtime via .split() and .join(). The script verifies that next-stage files are absent and a specific variable is set to 'YESSSSSSSS' before proceeding. If conditions are met, it copies itself to %PUBLIC%\Libraries and establishes persistence via a scheduled task with a 15-minute repeat interval using schtasks /create /sc minute /mo 15. The dropper then reverses hardcoded strings, strips junk delimiters, Base64-decodes, and writes to disk: either a LuaJIT interpreter executable (LuaJIT 2.1.0-beta3) with a disguised .ttf script file, or an AutoIt interpreter with accompanying script and encoded data.

Stage 2 — LuaJIT Loader (.ttf disguise): The .ttf file is not a font but a disguised Lua script. The LuaJIT interpreter executes it, passing the .ttf script as a parameter. The Lua loader performs a three-step decryption: (1) string reversal with symbol substitution (replacing ~@#:&*>< with ABCDa bcd), (2) Base64 decoding, and (3) a custom ROT cipher where the rotation key is derived from the first byte (formula: 94 - {first_byte} - 128), producing printable ASCII. The decrypted payload is Donut-generated shellcode. The Lua loader employs extensive anti-analysis: decoy memory allocation filled with suspicious strings and fake driver error messages (0xDEADBEEF, 0x1337C0DE), a PatchDonut64Header function that scans for and obfuscates Donut shellcode byte/string signatures using mask values 144 and 204, and in-memory XOR encryption/decryption cycles on shellcode with a consistent key.

Stage 2 (Alternate) — AutoIt Loader: An alternative variant drops the AutoIt interpreter, an obfuscated AutoIt script with randomized long-form variable names and string encryption, and an XOR-encrypted data file. The deobfuscated script launches C:\Windows\Syswow64\colorcpl.exe as a suspended process, reads and decrypts the local data file with XOR, and uses low-level ntdll.dll functions (NtCreateThreadEx, NtAllocateVirtualMemory) for process injection, allocating oversized memory regions for evasion.

Stage 3 — Donut Shellcode & Reflective Loading: The final payload is wrapped using the Donut shellcode generator. Upon successful shellcode execution, Donut's built-in reflective loader maps and executes the payload directly in memory without touching disk, achieving a fully fileless state.

June 2026 Variant — Advanced Evasion: The latest variant introduces several sophisticated capabilities. API unhooking actively neutralizes userland EDR hooks. Hardware breakpoint neutralization defeats both Lua and native debuggers. AMSI and ETW bypass using 'xor eax, eax, ret' instruction sequences blinds .NET and script runtime inspection. Direct syscalls bypass userland API hooks entirely. The most notable innovation is VEH-based segmented shellcode encryption: the shellcode is partitioned into page-sized segments, each independently encrypted and marked PAGE_NOACCESS. A Vectored Exception Handler is registered to intercept access violations — when execution hits a protected page, the exception triggers the VEH which decrypts that block and restores execution permissions, providing segment-by-segment on-demand decryption.

Payloads: The campaign delivers a diverse set of commodity malware families. Agent Tesla performs credential theft, keystroke logging, screen capture, and clipboard monitoring. Remcos provides full remote administrative control. XWorm functions as a modular RAT and infostealer. Snake Keylogger (under the name 'Best Private LOGGER') uses the same collection module and coding style as Snake, with minor signature modifications — a VIP variant also adds anti-analysis capabilities and Wi-Fi harvesting. FortiGuard also detected Formbook in some JScript samples.

C2 Infrastructure: The campaign uses a mix of dynamic DNS (newremupdate.duckdns.org:2404), compromised mail servers (mail.teamengineersgroup.com, mail.allportcargoservice.com, mail.trimnt.com, mail.taikei-rmc-co.biz), and IP-based C2 endpoints (104.239.66.86:7004, 46.183.223.21:2404, 107.174.34.137:443). C2 communication uses both web protocols and mail protocol impersonation.

The loader's low detection rates stem from the .ttf file extension bypassing human inspection, fileless final payload execution evading disk scanning, AMSI/ETW bypass techniques blinding runtime inspection, API unhooking and direct syscalls bypassing userland EDR hooks, and Discord CDN abuse circumventing domain-level URL filtering. The campaign remains active as of the July 2026 publication.

MITRE ATT&CK techniques used in TL-2026-2402

Defense Evasion

T1027.002 Obfuscated Files or Information: Software Packing; T1027.007 Obfuscated Files or Information: Dynamic API Resolution; T1027.013 Encrypted/Encoded File; T1036.008 Masquerading: Masquerade File Type; T1055.012 Process Injection: Process Hollowing; T1140 Deobfuscate/Decode Files or Information; T1218 System Binary Proxy Execution; T1497.001 Virtualization/Sandbox Evasion: System Checks; T1620 Reflective Code Loading

Persistence

T1053.005 Scheduled Task/Job: Scheduled Task

Privilege Escalation

T1055 Process Injection

Collection

T1056.001 Input Capture: Keylogging

Execution

T1059.005 Visual Basic; T1059.006 Python; T1059.007 JavaScript; T1204.002 User Execution: Malicious File

Command and Control

T1071.001 Application Layer Protocol: Web Protocols

Initial Access

T1566.001 Spearphishing Attachment; T1566.002 Spearphishing Link

defense-impairment

T1685 Disable or Modify Tools; T1690 Prevent Command History Logging

Affected products and versions in The TTF Trap

  • Microsoft — Windows
    Vulnerable versions: 10; 11; Server 2019; Server 2022

Remediation for The TTF Trap

Immediate actions

  • Block C2 IPs (104.239.66.86, 46.183.223.21, 107.174.34.137) at perimeter firewall
  • Block C2 domains (newremupdate.duckdns.org, mail.teamengineersgroup.com, mail.allportcargoservice.com, mail.trimnt.com, mail.taikei-rmc-co.biz) at DNS/proxy layer
  • Block Discord CDN attachment URL at web proxy
  • Search endpoint telemetry for all published SHA256 hashes using EDR/AV
  • Hunt for processes originating from C:\Users\Public\Libraries\ directory

Workarounds

  • Disable WSH and restrict script execution for non-administrative users
  • Remove AutoIt and LuaJIT interpreters from endpoints where not business-required

Longer-term hardening

  • Restrict LuaJIT and AutoIt execution from user-writable directories via application control policies
  • Restrict Windows Script Host (wscript.exe/cscript.exe) for unprivileged users
  • Enable command-line logging (Sysmon Event ID 1, Windows Event 4688) across all endpoints
  • Deploy behavioral detection rules for scheduled task creation from user-writable paths
  • Monitor for VEH registration (AddVectoredExceptionHandler) followed by NtProtectVirtualMemory calls
  • Block dynamic DNS domains (*.duckdns.org) at proxy layer if not business-required
  • Implement DMARC email authentication to reduce phishing delivery

Timeline of The TTF Trap

  • Earliest Lua loader samples identified; simpler variant using string reversal, Base64, and ROT14 cipher with CreateRemoteThread process injection into a legitimate process
  • FortiGuard telemetry detects initial wave of phishing emails carrying obfuscated JScript droppers that deliver LuaJIT/.ttf disguised loaders
  • Campaign scales globally; multiple JScript dropper variants observed with increasing obfuscation complexity including control flow flattening and anti-tampering mechanisms
  • AutoIt loader variant deployed as alternative delivery mechanism, using suspended colorcpl.exe process injection with low-level ntdll.dll functions
  • June 2026 variant released with significant anti-analysis advancements: VEH-based segmented shellcode encryption, API unhooking, software and hardware breakpoint neutralization, AMSI/ETW bypass, and direct syscall invocation
  • Attackers begin using Discord CDN as payload staging infrastructure to host JS/downloader files on legitimate platform, evading URL filtering
  • Campaign remains active as of publication date; FortiGuard recommends behavioral detection and blocking of C2 infrastructure rather than hash-based blocking alone due to constant loader evolution
  • FortiGuard Labs publishes full technical analysis of the TTF Trap campaign, detailing the infection chain, C2 infrastructure, IOC list, and detection signatures

Sources cited for The TTF Trap

Detection coverage for TL-2026-2402

As of 2026-09-08, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2402 across Splunk SPL, Microsoft KQL and Sigma, covering 23 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
23 indicators of compromise · Red and above. Compare plans

Community OSINT corroboration for TL-2026-2402

3 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats