Attackers Conceal Phishing Lures Using Invisible Unicode Characters
Microsoft discovers a large-scale phishing campaign using invisible Unicode characters to evade email security filters. The method has been used in millions of finance-themed phishing messages.
Intelligence analysis by Qwen 2.5 (3B)

Microsoft finds a phishing campaign using invisible Unicode characters to bypass email security filters, targeting finance-related messages.
Attackers use invisible letters to hide bad stuff in emails. It's like putting a secret message in a word that looks normal, so email filters can't see it.
Analysis
Microsoft discovered a large-scale phishing campaign using this technique, which peaked at up to 2.37 million daily messages in late February. Although the volume has dropped gradually in May, the operation is still active. The method has been used in millions of finance-themed phishing messages and works as intended, although Defender still caught over 99% of the messages based on other signals (sender, IP, domain, reputation checks).
Key points
- Attackers use invisible Unicode characters to hide malicious instructions in emails.
- This technique has been used in millions of finance-themed phishing messages.
- Email security filters can still catch most of these messages, but improvements are needed.
By improving email security filters, we can catch more of these hidden messages and keep them from reaching people's inboxes.
If attackers keep improving their techniques, it might be harder to catch these hidden messages, putting more people at risk.



