logo

“TTF Trap” Phishing Emails Use Fake Font Files to Deliver Windows Malware

ID: e7d09cfd-2d3b-5f21-a3e3-0408c1072bf1

STIX ID: report--e7d09cfd-2d3b-5f21-a3e3-0408c1072bf1

Feed Name: HackRead

Threat Score
75/100

Date Published: 2026-07-17

Date Updated: 2026-07-18

Author: Waqas

...
...

FortiGuard Labs has identified a high-risk phishing campaign called “TTF Trap” that tricks recipients into opening archives containing obfuscated JScript which drops legitimate interpreters and disguised `.ttf` files that are actually executable Lua/AutoIt scripts. The interpreters decrypt and run loaders (including Donut shellcode and process injection via `colorcpl.exe`) to install info-stealers and RATs such as Agent Tesla, Remcos, XWorm, and Snake Keylogger. Organizations should inspect file contents and behavior, restrict script interpreters (Windows Script Host, AutoIt, LuaJIT), enable sandboxing that opens nested archives and follow embedded links, and treat unexpected `.ttf` attachments in business documents as suspicious.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.