# The TTF Trap — Global Campaign Using Low-Detection Lua Loader Disguised as TrueType Font Files to Deploy RATs and Infostealers

> Since late March 2026, a large-scale global phishing campaign delivers fileless Lua-based loaders disguised as .ttf (TrueType Font) files. The multi-stage infection chain progresses from phishing email to obfuscated JScript dropper, then LuaJIT or AutoIt loader executing Donut shellcode via reflective loading, ultimately deploying Agent Tesla, Remcos, XWorm, Snake Keylogger (Best Private LOGGER variant), and Formbook. The Lua loader has evolved from a simpler October 2025 variant using CreateRemoteThread to a sophisticated June 2026 version employing Vectored Exception Handler-based segmented encryption, API unhooking, AMSI/ETW bypass, and breakpoint neutralization, achieving very low detection rates.

- **Published:** 2026-09-08T00:00:00Z
- **Last reviewed:** 2026-09-08T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-2402
- **ID:** TL-2026-2402
- **Severity:** HIGH
- **Category:** MALWARE
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 23 (full data via the Threadlinqs MCP server — Purple tier)

## Description

The TTF Trap campaign represents a sophisticated, multi-stage malware delivery operation that has remained largely undetected since its inception due to novel evasion techniques and a carefully layered infection chain. First observed by FortiGuard Labs via samples dating to October 2025, the campaign escalated significantly in late March 2026 and continued evolving through June 2026.

Initial Access & Delivery: Attackers send phishing emails impersonating well-known companies using business cooperation and payment-related lures. These emails contain compressed archives (ZIP/RAR) or download links pointing to malicious payloads hosted on legitimate services. One confirmed staging URL abuses Discord's CDN infrastructure: hxxps://cdn.discordapp.com/attachments/1499192125093449759/1511147377979818074/F10097782_Request-9200090_0990.PDF.JS.

Stage 1 — JScript Dropper: The archive contains an obfuscated JScript file employing heavy anti-analysis: string array mapping (critical strings accessed by index), control flow flattening (complex branching to confuse analysis), and anti-tampering integrity checks. ActiveX object names and output file paths use junk delimiters removed at runtime via .split() and .join(). The script verifies that next-stage files are absent and a specific variable is set to 'YESSSSSSSS' before proceeding. If conditions are met, it copies itself to %PUBLIC%\Libraries and establishes persistence via a scheduled task with a 15-minute repeat interval using schtasks /create /sc minute /mo 15. The dropper then reverses hardcoded strings, strips junk delimiters, Base64-decodes, and writes to disk: either a LuaJIT interpreter executable (LuaJIT 2.1.0-beta3) with a disguised .ttf script file, or an AutoIt interpreter with accompanying script and encoded data.

Stage 2 — LuaJIT Loader (.ttf disguise): The .ttf file is not a font but a disguised Lua script. The LuaJIT interpreter executes it, passing the .ttf script as a parameter. The Lua loader performs a three-step decryption: (1) string reversal with symbol substitution (replacing ~@#:&*>< with ABCDa bcd), (2) Base64 decoding, and (3) a custom ROT cipher where the rotation key is derived from the first byte (formula: 94 - {first_byte} - 128), producing printable ASCII. The decrypted payload is Donut-generated shellcode. The Lua loader employs extensive anti-analysis: decoy memory allocation filled with suspicious strings and fake driver error messages (0xDEADBEEF, 0x1337C0DE), a PatchDonut64Header function that scans for and obfuscates Donut shellcode byte/string signatures using mask values 144 and 204, and in-memory XOR encryption/decryption cycles on shellcode with a consistent key.

Stage 2 (Alternate) — AutoIt Loader: An alternative variant drops the AutoIt interpreter, an obfuscated AutoIt script with randomized long-form variable names and string encryption, and an XOR-encrypted data file. The deobfuscated script launches C:\Windows\Syswow64\colorcpl.exe as a suspended process, reads and decrypts the local data file with XOR, and uses low-level ntdll.dll functions (NtCreateThreadEx, NtAllocateVirtualMemory) for process injection, allocating oversized memory regions for evasion.

Stage 3 — Donut Shellcode & Reflective Loading: The final payload is wrapped using the Donut shellcode generator. Upon successful shellcode execution, Donut's built-in reflective loader maps and executes the payload directly in memory without touching disk, achieving a fully fileless state.

June 2026 Variant — Advanced Evasion: The latest variant introduces several sophisticated capabilities. API unhooking actively neutralizes userland EDR hooks. Hardware breakpoint neutralization defeats both Lua and native debuggers. AMSI and ETW bypass using 'xor eax, eax, ret' instruction sequences blinds .NET and script runtime inspection. Direct syscalls bypass userland API hooks entirely. The most notable innovation is VEH-based segmented shellcode encryption: the shellcode is partitioned into page-sized segments, each independently encrypted and marked PAGE_NOACCESS. A Vectored Exception Handler is registered to intercept access violations — when execution hits a protected page, the exception triggers the VEH which decrypts that block and restores execution permissions, providing segment-by-segment on-demand decryption.

Payloads: The campaign delivers a diverse set of commodity malware families. Agent Tesla performs credential theft, keystroke logging, screen capture, and clipboard monitoring. Remcos provides full remote administrative control. XWorm functions as a modular RAT and infostealer. Snake Keylogger (under the name 'Best Private LOGGER') uses the same collection module and coding style as Snake, with minor signature modifications — a VIP variant also adds anti-analysis capabilities and Wi-Fi harvesting. FortiGuard also detected Formbook in some JScript samples.

C2 Infrastructure: The campaign uses a mix of dynamic DNS (newremupdate.duckdns.org:2404), compromised mail servers (mail.teamengineersgroup.com, mail.allportcargoservice.com, mail.trimnt.com, mail.taikei-rmc-co.biz), and IP-based C2 endpoints (104.239.66.86:7004, 46.183.223.21:2404, 107.174.34.137:443). C2 communication uses both web protocols and mail protocol impersonation.

The loader's low detection rates stem from the .ttf file extension bypassing human inspection, fileless final payload execution evading disk scanning, AMSI/ETW bypass techniques blinding runtime inspection, API unhooking and direct syscalls bypassing userland EDR hooks, and Discord CDN abuse circumventing domain-level URL filtering. The campaign remains active as of the July 2026 publication.

## MITRE ATT&CK

- T1566.001 Spearphishing Attachment
- T1566.002 Spearphishing Link
- T1204.002 User Execution: Malicious File
- T1059.007 JavaScript
- T1059.005 Visual Basic
- T1059.006 Python
- T1053.005 Scheduled Task/Job: Scheduled Task
- T1027.002 Obfuscated Files or Information: Software Packing
- T1027.013 Encrypted/Encoded File
- T1036.008 Masquerading: Masquerade File Type
- T1140 Deobfuscate/Decode Files or Information
- T1055.012 Process Injection: Process Hollowing
- T1620 Reflective Code Loading
- T1685 Disable or Modify Tools
- T1690 Prevent Command History Logging
- T1027.007 Obfuscated Files or Information: Dynamic API Resolution
- T1497.001 Virtualization/Sandbox Evasion: System Checks
- T1218 System Binary Proxy Execution
- T1055 Process Injection
- T1056.001 Input Capture: Keylogging
- T1071.001 Application Layer Protocol: Web Protocols

## Sources

- [The TTF Trap: A Global Campaign of a Low-Detection Lua Loader](https://www.fortinet.com/blog/threat-research/the-ttf-trap-a-global-campaign-of-a-low-detection-lua-loader)
- [Fake TTF Files Deliver Stealthy Malware in Global Phishing Campaign](https://www.csoonline.com/article/4198165/fake-ttf-files-deliver-stealthy-malware-in-global-phishing-campaign.html)
- [Phishing Campaign Hides Lua Loader as TrueType Font File](https://www.infosecurity-magazine.com/news/phishing-lua-loader-truetype-font/)
- [TTF Trap: Fake Font Files Hide a Stealthy Lua Loader](https://securityonline.info/ttf-trap-lua-loader/)
- [The TTF Trap: Technical Breakdown and Detection Guidance](https://cyfar.ca/posts/the-ttf-trap-a-global-campaign-of-a-low-detection-lua-loader)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-2402
