All incidents

TFF Trap fileless phishing campaign distributes multiple RATs

incidentopenJul 16, 2026 — Jul 20, 2026
TFF Trap fileless phishing campaign distributes multiple RATs

THE TFF Trap phishing campaign has been observed distributing multiple remote access trojans through fileless techniques that lure victims with spoofed business emails, as detailed in Fortinet’s research.

Once executed, the loader fetches and launches payloads such as Agent Tesla and Remcos, which harvest credentials and enable remote control, according to analysis by Dark Reading.

Phishing messages carry compressed archives that contain a benign‑looking .ttf file; the font file actually holds the malicious Lua script, a technique highlighted by Infosecurity Magazine.

FortiGuard Labs first noted the activity in March 2026, with a spike in detections observed through mid‑July 2026. The campaign appears to be financially motivated, targeting Windows environments across multiple sectors. No specific threat actor has been attributed, but the use of well‑known RATs suggests a criminal operation seeking quick returns.

The reliance on fileless delivery and BEC lures shows how attackers are moving beyond traditional malware droppers to blend social engineering with in‑memory execution. Defenders who focus solely on file extensions or disk‑based indicators are likely to miss the malicious behaviour. This trend underlines the need for detection based on process behaviour and script analysis.

Security teams should enable logging of PowerShell and Lua interpreter usage, and monitor for unexpected spawning of processes from Office applications. Email gateways ought to block archives that contain executable‑type content hidden inside font files, and apply sandboxing to inspect file behaviour. User training must stress caution when receiving unsolicited requests for urgent payments or document reviews, even if the sender appears familiar. Applying the principle of least privilege and disabling unnecessary scripting engines can reduce the attack surface.

Keeping endpoint detection and response tools up to date with behavioural analytics will help catch the memory‑resident stages of the attack. Network segmentation limits lateral movement if a host is compromised, while regular credential rotation reduces the value of stolen data. Organisations should review their incident response playbooks to include steps for investigating fileless infections and restoring clean states from trusted backups.

Intelligence briefing updated Jul 20, 2026

Root sourcewww.fortinet.com
Timeline Coverage

Swipe to explore timeline