[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fMMhM2jSAZMfzVrIutX1qL4rghjzaar-6VmvBPSShGk0":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":23,"created_at":24,"published_at":25,"article":26,"tags":30,"podcasts":49},"3dcd5019-8496-457e-ad82-9eb2ec208cee","phishing-campaign-hides-malware-in-fake-font-files-to-bypass-detection","7a131c75-da79-4a79-9f3a-37b5d9bc466f","Phishing Campaign Hides Malware in Fake Font Files to Bypass Detection","The 'TTF Trap' campaign exploits users' trust in familiar file types by disguising malicious Lua scripts as harmless TrueType Font (.ttf) files, bypassing both human judgment and conventional signature-based security tools. Attackers impersonate legitimate companies in phishing emails to add credibility, lowering the recipient's guard before delivering obfuscated payloads. Once executed, the malware family — including Agent Tesla, Remcos, XWorm, and Snake Keylogger — can silently steal credentials and establish persistent remote access. This attack matters because it demonstrates how file extension spoofing and obfuscation together can defeat layered defenses when users lack awareness and endpoint controls are misconfigured.","**Immediate actions:**\n- Train all employees to verify file types by true MIME type and content rather than relying on file extensions alone.\n- Block execution of scripting interpreters (e.g., Lua, AutoIt) in user-writable directories via application whitelisting or Group Policy.\n- Enable advanced email filtering rules that flag or quarantine compressed archives (.zip, .rar) containing uncommon or mismatched file extensions.\n\n**Long-term improvements:**\n- Implement an application control policy that restricts execution of unsigned or untrusted binaries on all endpoints.\n- Deploy anti-phishing simulation programs quarterly to continuously measure and improve employee detection rates.\n- Enforce least-privilege access so that even if malware executes, its ability to access credentials and establish persistence is limited.\n\n**Detection measures:**\n- Configure EDR\u002FXDR solutions to alert on suspicious child processes spawned by scripting interpreters or archive-extraction tools.\n- Enable DNS filtering and network-layer monitoring to detect and block command-and-control (C2) callback traffic associated with known malware families like Remcos and XWorm.\n- Centralize and continuously review email gateway and endpoint logs to identify patterns of repeated phishing attempts targeting specific departments.",[12,13,14,15,16,17,18,19,20,21,22],"CIS Control 2: Inventory and Control of Software Assets","CIS Control 9: Email and Web Browser Protections","CIS Control 10: Malware Defenses","CIS Control 14: Security Awareness and Skills Training","NIST SP 800-53 SI-3: Malicious Code Protection","NIST SP 800-53 AT-2: Security Awareness Training","NIST SP 800-53 SC-7: Boundary Protection","NIST SP 800-53 AU-6: Audit Record Review and Analysis","MITRE ATT&CK T1566.001: Spearphishing Attachment","MITRE ATT&CK T1027: Obfuscated Files or Information","GDPR Article 32: Security of Processing (credential theft risk to personal data)","published","2026-07-17T14:20:24.776558+00:00","2026-07-17T14:20:24.5+00:00",{"id":7,"url":27,"slug":28,"title":29},"https:\u002F\u002Fhackread.com\u002Fttf-trap-phishing-fake-font-files-windows-malware\u002F","ttf-trap-phishing-emails-use-fake-font-files-to-deliver-windows-malware-589d48","“TTF Trap” Phishing Emails Use Fake Font Files to Deliver Windows Malware",[31,37,43],{"id":32,"name":33,"slug":34,"description":35,"color":36},"1732a005-556e-411c-a9db-5edec3058571","Logging & Monitoring","logging-monitoring","Missing logs, no alerting, blind spots","#a855f7",{"id":38,"name":39,"slug":40,"description":41,"color":42},"7261eb8f-acd4-4d93-a489-7fdd652ec0ea","Security Awareness","security-awareness","Phishing, social engineering, human error","#22c55e",{"id":44,"name":45,"slug":46,"description":47,"color":48},"859cf0ad-a7e9-42bb-a75d-bac6511fa5d5","Configuration Management","configuration-management","Misconfigs, default credentials, exposed services","#eab308",[50],{"id":51,"date":52,"edition":53,"title":54,"audio_url":55},"55bf5450-6844-47b4-b6f1-78a621e9cb48","2026-07-18","afternoon","ThreatNoir Weekend Brief — July 18","https:\u002F\u002Fcdn.threatnoir.com\u002Fpodcasts\u002F2026-07-18\u002Fthreatnoir-afternoon-brief-2026-07-18.mp3"]