Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Indicators The TTF Trap: A Global Campaign of a Low-Detection Lua Loader

mail.teamengineersgroup.com

TLP:CLEAR
Active

Domain

Description

Since late March 2026, a large-scale phishing campaign has been deploying malware including Agent Tesla, Remcos, XWorm, and Best Private LOGGER through fileless techniques and low-detection Lua-based loaders. Attackers impersonate well-known companies using business cooperation lures to distribute malicious archives containing obfuscated JavaScript files. These scripts deploy either AutoIt or LuaJIT interpreters alongside disguised scripts masquerading as TrueType Font (.ttf) files. The Lua loaders employ sophisticated anti-analysis techniques including custom ROT ciphers, decoy memory allocation, and Donut shellcode generation for reflective in-memory payload execution. The campaign evolved from simpler implementations in October 2025 to highly complex versions by June 2026, incorporating API unhooking and advanced debugging countermeasures. Victims are ultimately infected with Remote Access Trojans and infostealers that enable full system control and extensive data exfiltration.

Sightings (0)

No sightings recorded yet

Details

Name / Label
The TTF Trap: A Global Campaign of a Low-Detection Lua Loader
Pattern Type
STIX
Confidence
75%
Valid From
Jul 17, 2026 02:00
Total Sightings
0
Added
Jul 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.

Record Sighting

Record an observation of mail.teamengineersgroup.com

Sighting Type
Source
Comment
Leaving Threaticon

This link opens an external site that isn't part of the platform.