As cited
Copy frozen at (site build).
threat intel
Phishing Campaign Sends Millions of Emails Using Invisible Unicode to Evade Filters
Microsoft has detected a high-volume phishing campaign that uses invisible Unicode tag characters to split words like 'funding' and evade email security filters. The technique embeds zero-width characters within keywords to prevent detection while maintaining readability to recipients. The campaign demonstrates an evolution in filter-evasion tactics beyond the use of invisible characters to mislead artificial intelligence (AI) models.
Why it matters: Email security teams and organizations relying on content-based filtering need to assess whether their systems can detect Unicode tag character insertion; this campaign shows attackers are refining methods to bypass widely deployed defenses.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
threat intel
Phishing Campaign Sends Millions of Emails Using Invisible Unicode to Evade Filters
Microsoft has detected a high-volume phishing campaign that uses invisible Unicode tag characters to split words like 'funding' and evade email security filters. The technique embeds zero-width characters within keywords to prevent detection while maintaining readability to recipients. The campaign demonstrates an evolution in filter-evasion tactics beyond the use of invisible characters to mislead artificial intelligence (AI) models.
Why it matters: Email security teams and organizations relying on content-based filtering need to assess whether their systems can detect Unicode tag character insertion; this campaign shows attackers are refining methods to bypass widely deployed defenses.
- Source published
- First seen by Cybersecurity Tracker