FortiGuard Labs has been tracking a large-scale phishing campaign active since late March 2026 that uses heavily obfuscated JScript droppers to deploy Lua- or AutoIt-based loaders disguised as .ttf font files. The loaders employ multi-layered evasion techniques including string array mapping, control flow flattening, decoy memory allocation, Donut shellcode patching, and page-guard-based shellcode execution. The final payloads include Agent Tesla, Remcos, XWorm, and a Snake Keylogger variant branded as 'Best Private LOGGER.' The campaign impersonates legitimate businesses via business email compromise and has evolved significantly from October 2025 to June 2026, adding API unhooking, hardware breakpoint neutralization, and segmented VEH-based shellcode decryption. IOCs, C2 addresses, and file hashes are provided.