A global phishing campaign named "TTF Trap" was disclosed by FortiGuard Labs on July 16, 2026, which utilizes a low-detection Lua loader disguised as a TrueType Font (.ttf) file. The loader delivers various malware strains including Remcos, Agent Tesla, XWorm, and Snake Keylogger, targeting any Windows organization. The attackers use phishing emails with ZIP/RAR archives or download links that appear legitimate to deceive victims.
The campaign has been ongoing since late March 2026, with sophisticated techniques to evade detection and ensure persistence on infected systems. Detection guidance includes scrutinizing emails for potential threats, particularly those involving .ttf files.