ir-26-201-001 (1)

31204746892?profile=RESIZE_400xAn email that appears to contain a shipping document, payment request, or business proposal can infect a Windows computer, even if one of its main components has a .ttf extension.

FortiGuard Labs has named the operation “TTF Trap” after finding widespread phishing activity that uses disguised font files and low-detection Lua loaders.  The campaigns have been active since late March 2026, although researchers traced early versions of the loader to October 2025.  Fortinet rates the threat as High