Malicious File Extensions: Inspect The Bytes, Not The Name

Cybercriminals are now using ordinary font files to deliver low-detection malware.

According to research by experts, a global phishing campaign is actively utilizing heavily obfuscated JavaScript and a Lua-based loader that pose as a TrueType Font ("TTF") file in order to bypass security while it drops RATs and infostealers.

Malware families deployed include Agent Tesla, Remcos, XWorm, and a Snake Keylogger variant called Best Private LOGGER. This malware is capable of stealing credentials and establishing persistence in compromised systems.

This campaign has been active since at least March 2026.

Victims receive phishing emails impersonating well-known companies designed to trick them into opening compressed archives. These archives contain the compressed JavaScript that enables persistence and a malicious script inside a .ttf extension.

The .ttf extension, a fake font file, runs multiple de-obfuscation steps before decrypting and executing shellcode directly into memory.

Source: https://www.csoonline.com/article/4198165/fake-ttf-files-deliver-stealthy-malware-in-global-phishing-campaign.html

Commentary

These recent cyber attacks are utilizing a file extension change to bypass controls that rely on extension for inspection.

File extensions are metadata. They describe what a file claims to be, not what it actually is. When these file extensions are treated as an assertion of file type, mail gateways and endpoints may inspect the file with the wrong tools, failing to catch malware.

The actual content of the file must be inspected. Inspection at the mail gateway and on the endpoint identifies real file types by looking at the actual file content. A file that says .ttf but whose bytes describe a script or archive can be recognized and treated appropriately, not simply as a font.

These attacks are still being perpetrated using the oldest technique in the cyber attack book - phishing.

Cybersecurity training that focuses on identifying, avoiding, and reporting phishing messages will always be a valuable tool in any cyber attack defense tool kit.

Training should also include realistic simulations to teach staff how to recognize phishing messages in many different forms.

The final takeaway is that file extensions may lie. Organizations should add content inspection at the mail gateway and endpoints as cybersecurity control to reduce the likelihood of successful campaigns that rely on malicious file extensions. That, combined with continued cybersecurity training about phishing, may help avoid the risks.

Finally, your opinion is important to us. Please complete the opinion survey:

Product

Articles

Ignoring Pay Disparity Claims: A Risky Strategy For Healthcare Employers

The EEOC sued a healthcare employer and alleged a female employee was paid far less than her male coworker. We discuss.

Why Relying On Restitution Is Not A Good Bet

A tribal organization suffered a loss of nearly $5M after an employee's embezzlement scheme. We discuss why restitution does not always equal full recovery.

Staffing Shortage Is No Defense To PUMP Charges

A medical center was investigated by the U.S. Department of Labor after allegations of failing to allow breast milk pump breaks for nursing workers in violation of the PUMP Act. We examine why staffing shortages do not dictate breaks.

The Multi-Step Process For Healthcare Employers When Evaluating Accommodation Requests

A healthcare employer's leave policies lead to a sizeable disability discrimination settlement with the EEOC. Learn more about this case and about the difficulty of proving undue hardship.

One Controller, Higher Threat: The Embezzlement Risk Of Too Much Control

A controller of a small family textile company in California pled guilty and was sentenced to eight years in prison for embezzling more than $3.2M. We comment on the internal controls that can help employers lower their risk.