logo

Inboxfuscation: Because Rules Are Meant to Be Broken

ID: 88532824-0c51-5153-8814-5cc9fa769c63

STIX ID: report--88532824-0c51-5153-8814-5cc9fa769c63

Feed Name: Cloud Chronicles

Threat Score
30/100

Date Published: 2025-09-11

Date Updated: 2026-07-29

Author: [email protected] (Andi Ahmeti)

...
...

This report documents research into "Inboxfuscation," a set of Unicode-based obfuscation techniques that can be used to create malicious Microsoft Exchange inbox rules which evade traditional ASCII/keyword-based detection. It catalogs affected Unicode character classes (mathematical alphanumerics, zero-width characters, bidirectional controls, enclosed alphanumerics), demonstrates functional tricks (forwarding to Calendar, null/whitespace conditions, size normalization), presents hypothetical APT-style scenarios, and provides a detection framework and remediation actions for defenders; the authors note the techniques are feasible but not yet observed in active campaigns.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.