
“TTF Trap” Uses Fake Font Files to Drop Malware
FortiGuard Labs reports an active phishing operation (“TTF Trap”) where emails posing as invoices, shipping documents, or business proposals deliver an archive…
Researchers report a real, ongoing phishing campaign where attackers impersonate well-known companies and send business or payment-themed emails that trick recipients into opening a compressed attachment. Inside is heavily obfuscated script and a file disguised as a TrueType font (.ttf) that ultimately installs credential-stealing malware and remote-access tools on Windows systems.
This phishing campaign impersonates well-known companies and uses business cooperation or payment themed emails to convince recipients to open a compressed archive attachment. Inside the archive is heavily obfuscated JavaScript/JScript that establishes persistence and then drops either a legitimate AutoIt executable or a LuaJIT interpreter, along with a malicious script packaged inside a file with a .ttf extension. That fake font file is actually a Lua-based loader that runs multiple layers of de-obfuscation before decrypting and executing shellcode directly in memory, a fileless approach that helps it evade detection. The end result is deployment of remote access tools and infostealers, including Agent Tesla, Remcos, XWorm, and a Snake Keylogger variant.
The campaign relies on a combination of brand impersonation and a familiar business pretext, either a partnership proposal or a payment/invoice notice, to get a recipient to open a compressed attachment without hesitation. Because the payload is hidden inside a file disguised as a font, it exploits an assumption that file extensions reflect actual file type or intent. As one source in the reporting put it, security controls cannot treat a file extension as proof of file type or intent. The technical sophistication of the loader chain only matters because a person first opens the email and the attachment.
Organizations should treat unexpected compressed attachments as high-risk, particularly when tied to business cooperation or payment themes, and encourage verification through a known contact method before opening. Training should focus on the human decision point rather than only technical detail, since the most sophisticated evasion techniques still depend on someone opening an email that looks trustworthy and acting on it. Limiting what stolen credentials can reach through least privilege, requiring re-authentication for sensitive systems, and monitoring for anomalous session behavior can reduce the impact if a phishing email does succeed. Relevant MITRE ATT&CK techniques referenced in this campaign include spearphishing attachment (T1566.001), user execution of a malicious file (T1204.002), obfuscated files or information (T1027), and JavaScript-based scripting execution (T1059.007), which map to detection and response opportunities across the kill chain.
Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.
Victims open a compressed attachment from a phishing email that claims to be about business cooperation or payment. Inside is obfuscated script that drops a file disguised as a .ttf font, which is actually a Lua-based loader that decrypts and runs shellcode in memory.
Observed payloads include Agent Tesla, Remcos, XWorm, and a Snake Keylogger variant called Best Private LOGGER, all used for credential theft and persistent access on Windows systems.
File extensions are not proof of file type or intent. A font file extension looks harmless to most employees and can slip past assumptions built into everyday email handling.
Finance, accounts payable, sales, business development, procurement and executive assistant roles are commonly targeted because the pretexts center on payment requests and business cooperation.
You get an email: "Business cooperation / partnership proposal" from a big-name company, with a ZIP attached. Inside that ZIP is a script and a file that looks like a TrueType font, .ttf. But this "font" is actually a Lua-based loader that quietly drops Agent Tesla, Remcos, XWorm, even a Snake Keylogger variant. Here’s the trick: the email looks like normal business, cooperation or payment, big brand name, but the workflow is weird. Real partners don’t send surprise ZIPs where a "font" file runs like a program. If you get a "business cooperation" or "payment" email with a ZIP, stop. Don’t open the archive, call or message your known contact at that company and confirm first.

FortiGuard Labs reports an active phishing operation (“TTF Trap”) where emails posing as invoices, shipping documents, or business proposals deliver an archive…

A real, ongoing phishing campaign is tricking recipients into opening malicious archives that appear to contain harmless TrueType font files (.ttf) but…

Researchers at Unit 42 reported a real espionage campaign targeting organizations using Zimbra webmail, including government, defense, transportation and…

A Japanese industrial manufacturer was targeted by the SilverFox group using an invoice-themed phishing email that kicked off a multi-stage malware chain. The…

Researchers reported a real campaign by the China-based Silver Fox group against a Japanese industrial manufacturer. The attack starts with an invoice-themed…

A state-sponsored campaign in South Korea used spear-phishing and hacked “trusted” local websites to infect visitors who had vulnerable AnySign4PC installed.…