A global phishing campaign dubbed TTF Trap is using business email compromise lures and impersonation of trusted brands such as FedEx to infect Windows users with remote access Trojans and infostealers. Fortinet said the operation begins with phishing emails carrying or linking to ZIP or RAR archives, then launches heavily obfuscated JavaScript that establishes persistence and triggers a disguised loader hidden inside a fake .ttf font file.
The loader runs through legitimate LuaJIT or AutoIt interpreters and uses layered obfuscation, in-memory execution, API unhooking, anti-analysis checks, and reflective loading to avoid detection while keeping payloads off disk. Researchers observed the campaign since late March and said related loader code dates back to October 2025; malware delivered in the operation includes Agent Tesla, Remcos, XWorm, Best Private Logger, and Snake Keylogger variants, with the apparent goal of stealing data and maintaining remote access for follow-on attacks.

Get the infrastructure and lures behind it.
3 events from the most recent confirmed update back to the earliest known activity.
Fortinet said code related to the loader used in the TTF Trap campaign can be traced back to October 2025, indicating earlier development or prior use of the tooling before the phishing activity observed in 2026.
Fortinet publicly reported the campaign's evasion methods, including use of LuaJIT or AutoIt interpreters, in-memory execution, API unhooking, and reflective loading. It also released indicators of compromise such as URLs, scripts, and command-and-control addresses to support detection and response.
Fortinet reported that the large-scale phishing campaign dubbed TTF Trap has operated since late March 2026, using BEC-style lures and impersonation of trusted brands such as FedEx to target Windows users. The campaign delivers loaders via obfuscated JavaScript and fake .ttf files to deploy malware including Agent Tesla, Remcos, XWorm, Best Private Logger, and Snake Keylogger variants.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.