Tag
high
advisory
CastleLoader Malware Loader and ClearFake Activity in July 2026
3 rules 7 TTPs 7 IOCsRed Canary reports heightened activity of the CastleLoader malware loader, which uses paste-and-run techniques and legitimate tools to deliver infostealers and RATs, alongside continued prevalence of the ClearFake activity cluster in June 2026.
malware
loader
infostealer
remote-access-trojan
paste-and-run
drive-by download
windows
3r
7t
7i
high
advisory
The TTF Trap: Global Phishing Campaign Leverages Obfuscated JScript and Lua Loaders for RATs and Infostealers
7 TTPsFortiGuard Labs identified a global phishing campaign employing obfuscated JScript, disguised TrueType Font (.ttf) files, and Lua loaders to deliver remote access Trojans (RATs) and infostealers to victims.
phishing
loader
jscript
lua
rat
infostealer
malware
7t