Researchers reported a large-scale phishing campaign targeting Windows users with malicious archives that masquerade as business cooperation or payment-related documents from well-known companies. The infection chain uses heavily obfuscated JScript droppers and an AutoIt- or Lua-based loader disguised as a TrueType font (.ttf) file, enabling a largely fileless compromise path designed to avoid detection. Security reporting described the operation as global in scope, with lures crafted to persuade recipients to open fake font files that trigger the malware delivery process.
The campaign has deployed multiple commodity malware families, including Agent Tesla, Remcos, XWorm, and Best Private LOGGER, the latter assessed as a variant of Snake Keylogger based on shared modules and coding patterns. Researchers said the loader evolved significantly from late 2025 through mid-2026, adding anti-analysis features such as junk code, string obfuscation, API unhooking, breakpoint neutralization, Donut shellcode signature patching, decoy memory, and segmented shellcode decryption through a Vectored Exception Handler. Published indicators include domains, IP addresses, a Discord-hosted malicious JavaScript file, and SHA-256 hashes to support enterprise detection and threat hunting.

Get the infrastructure and lures behind it.
3 events from the most recent confirmed update back to the earliest known activity.
Researchers published technical details and detection artifacts for the campaign, including infrastructure and file-based indicators such as domains, IP addresses, a Discord-hosted malicious JavaScript file, and SHA-256 hashes. The reporting also detailed the fileless multi-stage infection chain and evasion methods used by the loader.
The Fortinet report documents the Lua loader's evolution across samples from October 2025 through June 2026, showing increasing sophistication in anti-analysis, shellcode execution, and process injection techniques. It also links Best Private LOGGER to Snake Keylogger based on shared modules, coding style, and naming conventions.
Researchers observed a large-scale phishing campaign targeting Microsoft Windows organizations since late March 2026. The campaign used obfuscated JScript droppers and AutoIt or Lua-based loaders disguised as .ttf files to deliver malware including Agent Tesla, Remcos, XWorm, and Best Private LOGGER.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 43 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
3 references tracked. Mallory keeps watching after this page renders.
csoonline.com
Open sourcecommunity.gurucul.com
Open sourcefeeds.fortinet.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.