FortiGuard Labs has been tracking a large-scale phishing campaign active since late March 2026 that uses heavily obfuscated JScript droppers to deploy Lua- or AutoIt-based loaders disguised as .ttf font files. The loaders employ multi-layered evasion techniques including string array mapping, control flow flattening, decoy memory allocation, Donut shellcode patching, and page-guard-based shellcode execution. The final payloads include Agent Tesla, Remcos, XWorm, and a Snake Keylogger variant branded as 'Best Private LOGGER.' The campaign impersonates legitimate businesses via business email compromise and has evolved significantly from October 2025 to June 2026, adding API unhooking, hardware breakpoint neutralization, and segmented VEH-based shellcode decryption. IOCs, C2 addresses, and file hashes are provided.

10m read timeFrom feeds.fortinet.com
Post cover image
Table of contents
Initial AccessJScriptLua LoaderDecoy MemoryPatchDonut64HeaderOctober 2025June 2026AutoIt LoaderDonut Shellcode and PayloadBest Private LOGGERConclusionFortinet ProtectionsIOCs
13.7K Impressions