“TTF Trap” Phishing Emails Use Fake Font Files to Deliver Windows Malware

2026-07-17T20:51:43Z933614769138798ce4a3a28e77a6f69e085c2a0ba700febaba1bccbe3eefcb93
AD FSAI‑securityAsyncAPIBitLocker bypassClaude DesktopMicrosoft Patch TuesdayPromptInjectionSharePointTTFbrowser‑extensionscrypto‑theftfont‑based malwareincident responsemalwarenpmphishingsupply‑chainuser awarenessvulnerability managementzero‑day

What happened

Multiple notable incidents and advisories: a new “TTF Trap” phishing campaign uses fake font (.ttf) files to deliver Windows malware via shipping/invoice-themed lures; OkoBot malware targets crypto users using fake installers, ClickFix and hidden browser extensions to steal wallets and seed phrases; a PromptFiction flaw in Claude Desktop allowed one‑click hidden prompts that exposed chats and could enable remote code execution; Microsoft’s July 2026 Patch Tuesday addressed 622 CVEs including exploited AD FS and SharePoint zero‑days and a disclosed BitLocker bypass — immediate patching is urged

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
hackread
Record identifier
933614769138798ce4a3a28e77a6f69e085c2a0ba700febaba1bccbe3eefcb93
Enrichment time
2026-07-17T20:51:43Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · “TTF Trap” Phishing Emails Use Fake Font Files to Deliver Windows Malware · Baitaphish