← Blog · · df00tech

Attackers Hide Phishing Lures Using Invisible Unicode Characters to Bypass Email Filters

security-news technique

Security researchers have reported that threat actors are using an ASCII smuggling technique in phishing campaigns, embedding invisible Unicode characters into email content to evade email security filters, according to BleepingComputer.

What Was Reported

The technique reportedly relies on Unicode characters that render as invisible or blank to the recipient while still being present in the underlying text. By interspersing these characters within phishing lures, attackers can alter how automated scanning tools parse and match content against known malicious patterns, potentially allowing messages to slip past signature- and keyword-based email security filters without changing what a human reader visually sees.

Why It Matters for Defenders

Email security gateways and phishing detection tools that rely heavily on text-matching, keyword blocklists, or visual-to-text parity checks may be particularly exposed to this evasion approach. Because the visible content a user sees remains unchanged, this is primarily a detection-evasion technique rather than a new delivery or exploitation method — the underlying phishing lures themselves are not novel, but their ability to reach inboxes undetected may increase.

What Defenders Should Watch For

  • Review whether your email security stack normalizes or strips non-printing/invisible Unicode characters (e.g., zero-width spaces, Unicode tag characters, bidirectional control characters) before running content-matching or filtering logic.
  • Consider hunting for anomalous Unicode character sequences in email headers, subject lines, and body content, particularly characters outside expected printable ranges.
  • Evaluate whether existing keyword- or pattern-based phishing detection rules can be bypassed by inserting non-rendering characters between or within flagged terms, and test filter resilience accordingly.
  • Continue reinforcing user-facing controls (link inspection, sender verification, attachment sandboxing) since this technique targets automated filtering rather than human perception.

This is a developing report based on a single source and details on specific campaigns, actors, or targeted organizations were not disclosed. For the original reporting, see BleepingComputer's coverage.

Get new detections in your inbox

New ATT&CK coverage plus CISA KEV / CVE detection rules, roughly weekly. No spam, unsubscribe anytime.