BiDi Swap: The bidirectional text trick that makes fake URLs look real
ID: 9e8cb040-11ed-5ebd-b1c9-36a82bd26202
STIX ID: report--9e8cb040-11ed-5ebd-b1c9-36a82bd26202
Feed Name: Bleeping Computer
Varonis Threat Labs details a decade-old URL spoofing technique named BiDi Swap that exploits how browsers handle mixed right-to-left and left-to-right scripts (the Unicode Bidirectional Algorithm) to create deceptive-looking URLs for phishing. The report reviews related Unicode attacks (homograph and RTL override), demonstrates proof-of-concept payloads, compares browser mitigations (Chrome, Firefox, Edge, Arc), and offers recommendations for developers and users to reduce spoofing risk.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
