“TTF Trap” Phishing Emails Use Fake Font Files to Deliver Windows Malware

https://hackread.com/wp-content/uploads/2026/07/ttf-trap-phishing-fake-font-files-windows-malware-2.jpg

An email that appears to contain a shipping document, payment request, or business proposal can infect a Windows computer even when one of its main components carries a .ttf font extension.

FortiGuard Labs has named the operation “TTF Trap” after finding widespread phishing activity that uses disguised font files and low-detection Lua loaders. The campaigns have been active since late March 2026, although researchers traced early versions of the loader to October 2025. Fortinet rates the threat as High and says any organization using Windows could be targeted.

For context, TTF stands for TrueType Font, a common format used for fonts on Windows. In this campaign, the .ttf file is not a real font. Attackers use the familiar extension to disguise a malicious Lua script that installs malware when executed by a separate program.

Phishing Emails

The emails impersonate established companiesand address recipients with requests for orders, invoices,...

Copyright of this story solely belongs to hackread.com. To see the full text click HERE

Read more