An email that appears to contain a shipping document, payment request, or business proposal can infect a Windows computer, even if one of its main components has a .ttf extension.
FortiGuard Labs has named the operation “TTF Trap” after finding widespread phishing activity that uses disguised font files and low-detection Lua loaders. The campaigns have been active since late March 2026, although researchers traced early versions of the loader to October 2025. Fortinet rates the threat as High