"The TFF Trap" uses fileless techniques and loaders with low detection rates to deploy various RATs and stealers, including Agent Tesla, Remcos, XWorm, and Best Private Logger.

July 20, 2026

Attackers are impersonating well-known companies to drop various remote access Trojans (RATs) and infostealers in a wide-scale phishing campaign designed for maximum evasion. The campaign highlights how threat actors continue to evolve beyond traditional executable-based attacks, using a combination of disguised font files, Lua interpreters, and in-memory execution to bypass endpoint defenses.

Researchers at Fortinet since late March have observed the campaign, dubbed "The TFF Trap," which uses a combination of fileless techniques and Lua-based loaders with low detection rates to deploy various malware families, including Agent Tesla, Remcos, XWorm, and Best Private Logger, according to a report published last week. The name comes from attackers' use of a TrueType Font (.ttf) file to hide the AutoIT/Lua loader used to deliver malware.

"In these campaigns, the dropped executable serves as an interpreter, while the core loader script is disguised as a .ttf extension," Fortinet threat researchers Yurren Wan wrote in the report. "This disguised loader decrypts, loads, and executes the subsequent stage, which ultimately deploys the malware."