Security researchers at Fortinet say a phishing technique dubbed TTF Trap is using fake font files to infect Windows machines inside businesses. The campaign relies on emails that look routine at first glance, but hide malicious components behind a .ttf extension normally associated with font files.
According to the report, the emails are designed to blend into everyday office traffic. They may appear to contain shipping paperwork, payment-related requests, or business proposals, increasing the chance that an employee will open the file and trigger the infection chain on a company system.
Fortinet says the fake font files conceal Lua-based loaders, which are then used to deliver a range of known malware families. The payloads named in the report include Remcos, XWorm, Agent Tesla, and Snake Keylogger, showing that the tactic can support both remote-access malware and credential-stealing threats.
The findings highlight how attackers continue to disguise malware as common business documents and harmless-looking file types. For Windows users and corporate security teams, the campaign is another reminder that file extensions and familiar email themes can be manipulated to bypass suspicion and open the door to wider compromise.