Back to all lessons
Awareness Lessons
last month

Invisible Unicode Characters Used to Bypass Email Security Filters

Threat actors exploited ASCII smuggling — embedding invisible Unicode characters into finance-related keywords — to evade signature and keyword-based email security filters at scale, reaching over 2.37 million messages per day. The root issue lies in email security configurations that apply keyword detection against raw, un-normalized text, leaving a trivial but effective evasion gap. While Microsoft Defender mitigated over 99% of messages through supplementary signals, organizations relying solely on keyword-based filters would have been significantly exposed. This attack highlights how even well-established defensive controls can be undermined by subtle encoding tricks, and underscores the need for layered, technically robust detection pipelines. End users who receive such emails remain at risk of credential theft or financial fraud if they are not trained to recognize phishing cues beyond obvious keyword triggers.

Tactical Insight

Immediate actions

  • Configure email security gateways to normalize Unicode characters before applying any keyword-based content inspection rules.
  • Enable multi-signal phishing detection (e.g., sender reputation, link analysis, header anomalies) rather than relying solely on keyword matching.

Long-term improvements

  • Implement a layered email defense stack combining gateway filtering, sandboxing, and endpoint-level detection to reduce dependence on any single control.
  • Establish a regular review cycle for email security rule sets to account for emerging evasion techniques such as encoding manipulation and homoglyph attacks.
  • Integrate threat intelligence feeds that track novel phishing techniques so detection logic can be updated proactively.

User awareness & detection measures

  • Train employees to identify phishing indicators beyond email content, including unusual sender domains, unexpected financial requests, and suspicious links.
  • Deploy a user-reported phishing mechanism and ensure SOC analysts review submissions to detect campaigns that evade automated filters.
  • Monitor email telemetry and alert on sudden spikes in inbound message volume targeting finance-related keywords or departments.