216.73.216.197

The TTF Trap: A Global Campaign of a Low-Detection Lua Loader

· Published 16/07/2026 18:06

Export JSON

Essential information

Published
16/07/2026 18:06
Modified
Source / Author
AlienVault
Confidence
100/100
Report type(s)
threat-report
Labels / Tags
agent tesla autoit best private logger donut shellcode fileless execution infostealer lua loader obfuscation phishing campaign rat deployment remcos snake keylogger ttf disguise xworm
Related entities
39 indicators, 6 observables, 19 techniques (mitre), 5 malware

Description

Since late March 2026, a large-scale has been deploying malware including , , , and Best Private LOGGER through fileless techniques and low-detection Lua-based loaders. Attackers impersonate well-known companies using business cooperation lures to distribute malicious archives containing obfuscated JavaScript files. These scripts deploy either or LuaJIT interpreters alongside disguised scripts masquerading as TrueType Font (.ttf) files. The Lua loaders employ sophisticated anti-analysis techniques including custom ROT ciphers, decoy memory allocation, and Donut shellcode generation for reflective in-memory payload execution. The campaign evolved from simpler implementations in October 2025 to highly complex versions by June 2026, incorporating API unhooking and advanced debugging countermeasures. Victims are ultimately infected with Remote Access Trojans and infostealers that enable full system control and extensive data exfiltration.

External references