Analytics BIOC Informational

Suspicious Unicode character detected in email

Unicode characters can be used for obfuscation, allowing malicious actors to disguise harmful intent, URLs or attachments By embedding non-printing Unicode characters, attackers can bypass security filters and evade detection mechanisms Such characters may also be used for phishing attempts that appear legitimate to both users and security systems.

Module:
Email Security
Licensed by:
Email Security
Data source:
Microsoft 365 Emails
ATT&CK tactics: Defense Evasion (TA0005)
ATT&CK techniques: Masquerading (T1036) Impersonation (T1656)
Detector tags: Evasion Phishing
Attacker's goals:

Embedding suspicious Unicode characters in the email to appear legitimate, evade security filters and bypass detection mechanisms.

Investigative actions:

Check the email address for any unusual spellings, missing letters, or unknown domains. If the message contains attachments or links, scrutinize them for any suspicious indications. Monitor further actions taken, such as file downloads or access to potentially malicious links.

Test period:
N/A (single event)
Deduplication:
1 Day
3 variations:
  • Phishing terms obfuscation using Unicode characters detected in email Low (parent: Informational)
  • Words obfuscation using Unicode characters detected in email Informational
  • Multiple suspicious Unicode characters detected in email Informational