Find notable cyber news and cases, enriched with sources, timelines, and signals.

SHADOW#REACTOR fake .ttf phishing campaign targeting Windows systems

Campaign
First reported
Last updated
Happening score
H score 31
1 unique sources, 1 articles

Summary

Hide ▲

A large-scale phishing campaign is delivering RATs and infostealers to Windows systems by disguising a malicious script as a .ttf font file. The operation has been active since late March 2026 and uses fileless delivery to reduce detection. It combines business-cooperation lures, scheduled-task persistence, and in-memory execution to push payloads including Agent Tesla, Remcos, XWorm, and Best Private LOGGER.

Related Happenings

UAC-0099 fake Notepad++ plugin campaign

Campaign
H score31 First: 24.07.2026 09:50 Last: 24.07.2026 09:50 Sources 1

About this happening: A UAC-0099 phishing campaign is using a fake Notepad++ plugin chain to compromise Windows systems and deploy MATCHBOIL.V2 with scheduled-task persistence. The...

CISA patch guidance for Zimbra and SharePoint flaws

Advisory/Mitigation
H score56 First: 19.03.2026 08:05 Last: 19.03.2026 08:05 Sources 1

About this happening: CISA, NSA, and partner agencies issued a joint advisory on CVE-2025-66376, a stored XSS flaw in Zimbra Collaboration Classic UI that lets a crafted email r...

Timeline

  1. 16.07.2026 18:00 1 articles · 13d ago

    Fake .ttf Lua loader campaign targets Windows systems

    Initial Disclosure

    FortiGuard Labs identified a large-scale phishing campaign active since late March 2026 that disguises a malicious Lua loader as a .ttf TrueType font file on Windows systems. The chain uses business-cooperation lures and payment-themed phishing emails, copies itself to %PUBLIC%\Libraries, sets a scheduled task for persistence, and drops LuaJIT or AutoIt before delivering Donut shellcode that executes payloads in memory. FortiGuard Labs observed Remcos, Agent Tesla, XWorm, or Best Private LOGGER on victims, and a June 2026 build added segmented encryption that decrypted page-sized shellcode fragments with a Vectored Exception Handler.

    Show sources