mimile
mimile.ai
Back to feed
This event is part of a larger story
Массовые утечки и атаки: июль 2026 года
Read briefing

Fortinet warns of phishing campaign using fake TTF files to drop malware

AI digest

This digest was compiled by AI from multiple sources — links to the originals are below.

Fortinet warns of phishing campaign using fake TTF files to drop malware

Fortinet's FortiGuard Labs has uncovered a global phishing campaign that uses heavily obfuscated JavaScript and a Lua-based loader disguised as a TrueType Font file to deliver malware. The campaign, active since late March 2026, deploys Agent Tesla, Remcos, XWorm, and a Snake Keylogger variant. The attackers impersonate well-known companies with business-themed lures to trick victims into opening malicious archives.

Attack Technique

The phishing emails contain compressed archives with obfuscated JScript that establishes persistence and drops a legitimate Autolt executable or LuaJIT interpreter along with a malicious script with a .ttf extension. The fake font file acts as a Lua-based loader that performs multiple de-obfuscation steps before decrypting and executing shellcode in memory. The final payload is delivered using Donut shellcode, enabling fileless execution.

Malware Families

The campaign deploys Agent Tesla, Remcos, XWorm, and a Snake Keylogger variant known as Best Private LOGGER. New variants introduce segmented shellcode encryption, Vectored Exception Handler-based runtime decryption, AMSI and ETW bypasses, API unhooking, and other anti-analysis techniques to evade endpoint defenses.

Expert Commentary

Shane Barney, CISO at Keeper Security, noted that sophisticated evasion still relies on human error from phishing emails. Jason Soroko, senior fellow at Sectigo, emphasized that security controls cannot treat file extensions as proof of file type. The attackers' endgame is credential theft and long-term access.

What's Next

Fortinet recommends targeted mitigations and routine security hygiene to defend against these attacks. It remains unclear how widely the campaign has spread or whether new evasion techniques will emerge.

1 source

Fortinet warns of phishing campaign using fake TTF files to drop malware