The Phishing Email That Read Backwards in Its Own Source
ID: fa0817f0-5759-52a1-8735-20b03a51b30d
STIX ID: report--fa0817f0-5759-52a1-8735-20b03a51b30d
Feed Name: IRONSCALES
An e-signature spearphishing campaign targeted a senior executive by storing all visible copy as reversed printable ASCII and using CSS properties (unicode-bidi:bidi-override; direction:rtl) so the email rendered normally but bypassed source-level detectors; the message passed SPF/DKIM/ARC, used an aged unrelated sending domain and two click-trackers, and resolved to a malicious landing page with a press-and-hold human-verification interstitial. Recommended mitigations include reconciling rendered text against stored source, flagging inline unicode-bidi overrides, following click chains to final destinations, and verifying unexpected document notices inside the application rather than via email buttons.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
