CuraSec

Act active

High-Volume Phishing Campaign Uses Invisible Unicode to Split Keywords

2026-09-05 13:51 UTC · The Hacker News · read the source ↗ #phishing#email-security#evasion
  • Engineer — Plan: Audit email security gateway and filtering pipeline for Unicode normalization support; configure rules to strip or flag invisible Unicode tag characters (U+E0000 block) before keyword matching, as current filter logic may silently pass these.
  • SOC/IR — Act: Active high-volume campaign with a specific, huntable TTP: query recent inbound email logs for messages containing invisible Unicode tag characters interleaved within financial keywords; tune SEG/SIEM detections to flag this pattern going forward.
  • Leader — Learn: Novel evasion technique shows email filtering products may have a systematic blind spot around Unicode normalization; useful context when next reviewing email security vendor capabilities or during security questionnaire assessments.
This entry was curated and judged by AI (Claude) with automated enrichment (CISA KEV / EPSS / public PoC). Verify against the original source before acting. Found a bad verdict? Report it — confirmed errors go to the corrections log.