Inboxfuscation: Because Rules Are Meant to Be Broken
ID: 88532824-0c51-5153-8814-5cc9fa769c63
STIX ID: report--88532824-0c51-5153-8814-5cc9fa769c63
Feed Name: Cloud Chronicles
This report documents research into "Inboxfuscation," a set of Unicode-based obfuscation techniques that can be used to create malicious Microsoft Exchange inbox rules which evade traditional ASCII/keyword-based detection. It catalogs affected Unicode character classes (mathematical alphanumerics, zero-width characters, bidirectional controls, enclosed alphanumerics), demonstrates functional tricks (forwarding to Calendar, null/whitespace conditions, size normalization), presents hypothetical APT-style scenarios, and provides a detection framework and remediation actions for defenders; the authors note the techniques are feasible but not yet observed in active campaigns.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
