securityonline.info 7/22/2026, 2:31:56 PM · external

FortiGuard flags TTF Trap phishing with .ttf malware loader

FortiGuard flags TTF Trap phishing with .ttf malware loader
Developing story outage 3 articles tracked
TTF Trap phishing campaign uses fake font files to deliver RATs
CyberSIXT Evidence Panel
Primary Source fortinet.com

A global phishing campaign named "TTF Trap" was disclosed by FortiGuard Labs on July 16, 2026, which utilizes a low-detection Lua loader disguised as a TrueType Font (.ttf) file. The loader delivers various malware strains including Remcos, Agent Tesla, XWorm, and Snake Keylogger, targeting any Windows organization. The attackers use phishing emails with ZIP/RAR archives or download links that appear legitimate to deceive victims.

The campaign has been ongoing since late March 2026, with sophisticated techniques to evade detection and ensure persistence on infected systems. Detection guidance includes scrutinizing emails for potential threats, particularly those involving .ttf files.

View Primary Source Via securityonline.info

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline