logo

The Phishing Email That Read Backwards in Its Own Source

ID: fa0817f0-5759-52a1-8735-20b03a51b30d

STIX ID: report--fa0817f0-5759-52a1-8735-20b03a51b30d

Feed Name: IRONSCALES

Threat Score
70/100

Date Published: 2026-08-24

Date Updated: 2026-08-24

Author: [email protected] (Audian Paxson)

...
...

An e-signature spearphishing campaign targeted a senior executive by storing all visible copy as reversed printable ASCII and using CSS properties (unicode-bidi:bidi-override; direction:rtl) so the email rendered normally but bypassed source-level detectors; the message passed SPF/DKIM/ARC, used an aged unrelated sending domain and two click-trackers, and resolved to a malicious landing page with a press-and-hold human-verification interstitial. Recommended mitigations include reconciling rendered text against stored source, flagging inline unicode-bidi overrides, following click chains to final destinations, and verifying unexpected document notices inside the application rather than via email buttons.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.