An electronic mail that seems to comprise a transport doc, fee request, or enterprise proposal can infect a Home windows laptop even when one in all its essential elements carries a .ttf font extension.
FortiGuard Labs has named the operation “TTF Lure” after discovering widespread phishing exercise that makes use of disguised font recordsdata and low-detection Lua loaders. The campaigns have been lively since late March 2026, though researchers traced early variations of the loader to October 2025. Fortinet charges the risk as Excessive and says any group utilizing Home windows may very well be focused.
For context, TTF stands for TrueType Font, a typical format used for fonts on Home windows. On this marketing campaign, the .ttf file isn’t an actual font. Attackers use the acquainted extension to disguise a malicious Lua script that installs malware when executed by a separate program.
Phishing Emails
The emails impersonate established firms and handle recipients with requests for orders, invoices, transport paperwork, funds, or enterprise cooperation. Some messages comprise ZIP or RAR archives, whereas others present hyperlinks that obtain the archive. The sender creates a way of urgency to influence the recipient to open the included recordsdata.
Opening the archive launches a closely obfuscated JScript file full of junk code designed to hinder automated scanning and guide inspection. The script copies itself into the Home windows Public Libraries folder, creates a scheduled job for persistence, and decodes further recordsdata hidden inside its code.
Among the many dropped recordsdata is a legit AutoIt or LuaJIT interpreter accompanied by a malicious script. That script could use a .ttf extension, making it seem like a TrueType Font though its contents comprise executable Lua code. The interpreter reads the disguised file, decrypts its contents, and runs the subsequent stage.
As soon as decoded, the loader executes Donut shellcode immediately in reminiscence, lowering the malicious recordsdata written to disk. A associated AutoIt model launches the legit Home windows colorcpl.exe course of in a suspended state earlier than injecting and operating the payload inside it.
Fortinet’s evaluation discovered that newer loader variations added additional anti-analysis strategies to make debugging and detection harder.
The ultimate malware varies between assaults. FortiGuard Labs noticed Agent Tesla, Remcos, XWorm and several other Snake Keylogger variants, together with Finest Non-public LOGGER. These instruments can steal credentials and different data, report keystrokes or give attackers distant management of an contaminated laptop.
Knowledgeable Perspective
Jason Soroko, Senior Fellow at Sectigo, mentioned the marketing campaign exhibits why a filename or extension can’t affirm what a file accommodates. The interpreter, script and disguised font could seem much less suspicious when reviewed individually, however their mixed execution delivers distant entry instruments and information-stealing malware.
Soroko suggested organizations to examine file contents, conduct and execution context. Electronic mail gateways and sandboxes ought to open nested archives, comply with embedded obtain hyperlinks and determine scripts carrying deceptive extensions. The place they aren’t wanted, Home windows Script Host, AutoIt and LuaJIT needs to be restricted by way of utility management, notably in user-writable folders.
As a result of the loader has modified repeatedly, Soroko mentioned detection mustn’t rely solely on file hashes or command servers listed in revealed indicators. Monitoring must also cowl script interpreters launched from electronic mail or archive packages, uncommon use of colorcpl.exe, distant reminiscence allocation, course of injection, and shellcode execution.
Staff receiving surprising orders, invoices, or transport recordsdata ought to confirm the request with the supposed sender by way of a separate communication channel. A .ttf file inside a enterprise archive ought to by no means require an interpreter or script to run, and any request involving such recordsdata needs to be reported earlier than opening them.
(Picture by Brett Jordan on Unsplash)










