Hackers are using 'invisible' Unicode characters to sneak phishing lures into emails
- Microsoft reports phishing campaign using ASCII smuggling to bypass spam filters
- Attackers insert invisible characters into keywords, tricking filters and AI agents
- Defenders should normalize Unicode tags and flag unexpected invisible code points as suspicious
Cybercriminals are using the “ASCII smuggling” technique to make sure phishing emails pass security filters and land in people’s inboxes, experts have warned.
ASCII is a character encoding standard that turns characters and words humans can read into numeric values that computers can understand. It can also be used to create characters that aren’t even displayed on the screen (essentially “invisible” ones) but can still be read by the machine.
In a new report, security researchers from Microsoftfound crooks are abusing this fact to distribute phishing emails. Most email providers offer solutions that filter out spam emails. These filters look for certain keywords and phrases, such as “funding”, “credit”, “loan”, and similar, and...
Copyright of this story solely belongs to www.techradar.com. To see the full text click HERE