SHADOW#REACTOR fake .ttf phishing campaign targeting Windows systems
Campaign
Summary
Hide ▲
Show ▼
A large-scale phishing campaign is delivering RATs and infostealers to Windows systems by disguising a malicious script as a .ttf font file. The operation has been active since late March 2026 and uses fileless delivery to reduce detection. It combines business-cooperation lures, scheduled-task persistence, and in-memory execution to push payloads including Agent Tesla, Remcos, XWorm, and Best Private LOGGER.
Related Happenings
UAC-0099 fake Notepad++ plugin campaign
Campaign
H score31
First: 24.07.2026 09:50
Last: 24.07.2026 09:50
Sources 1
About this happening:
A UAC-0099 phishing campaign is using a fake Notepad++ plugin chain to compromise Windows systems and deploy MATCHBOIL.V2 with scheduled-task persistence. The...
UAC-0099 fake Notepad++ plugin campaign
CampaignAbout this happening: A UAC-0099 phishing campaign is using a fake Notepad++ plugin chain to compromise Windows systems and deploy MATCHBOIL.V2 with scheduled-task persistence. The...
CISA patch guidance for Zimbra and SharePoint flaws
Advisory/Mitigation
H score56
First: 19.03.2026 08:05
Last: 19.03.2026 08:05
Sources 1
About this happening:
CISA, NSA, and partner agencies issued a joint advisory on CVE-2025-66376, a stored XSS flaw in Zimbra Collaboration Classic UI that lets a crafted email r...
CISA patch guidance for Zimbra and SharePoint flaws
Advisory/MitigationAbout this happening: CISA, NSA, and partner agencies issued a joint advisory on CVE-2025-66376, a stored XSS flaw in Zimbra Collaboration Classic UI that lets a crafted email r...
Timeline
-
16.07.2026 18:00 1 articles · 13d ago
Fake .ttf Lua loader campaign targets Windows systems
Initial DisclosureFortiGuard Labs identified a large-scale phishing campaign active since late March 2026 that disguises a malicious Lua loader as a .ttf TrueType font file on Windows systems. The chain uses business-cooperation lures and payment-themed phishing emails, copies itself to %PUBLIC%\Libraries, sets a scheduled task for persistence, and drops LuaJIT or AutoIt before delivering Donut shellcode that executes payloads in memory. FortiGuard Labs observed Remcos, Agent Tesla, XWorm, or Best Private LOGGER on victims, and a June 2026 build added segmented encryption that decrypted page-sized shellcode fragments with a Vectored Exception Handler.
Show sources
- Phishing Campaign Hides Lua Loader as TrueType Font File — www.infosecurity-magazine.com — 16.07.2026 18:00