Fake TTF Files Conceal Malware in Global Phishing Campaign
A global phishing campaign is using a Lua-based malware loader disguised as a TrueType Font file to infect Windows systems while evading detection. Malicious archives delivered through business- and payment-themed emails launch obfuscated scripts that establish persistence and execute Agent Tesla, Remcos, XWorm, and Best Private LOGGER payloads directly in memory. Newer variants employ encrypted shellcode, security-tool bypasses, API unhooking, and anti-analysis techniques to steal credentials and maintain remote access. Organizations should strengthen identity controls, restrict unnecessary scripting tools, and monitor behavioral indicators such as process injection and in-memory code execution.
Reference: csoonline.com