Saturday, May 24, 2025
HomeCyber Security NewsZeroFont Phishing: Hackers Manipulating Font Size to Bypass Office 365 Security

ZeroFont Phishing: Hackers Manipulating Font Size to Bypass Office 365 Security

Published on

SIEM as a Service

Follow Us on Google News

A new but ancient technique for Phishing emails has been recently identified called ZeroFont Phishing. Threat actors have followed several tactics for sending phishing emails, bypassing all the security mechanisms.

However, using this technique, threat actors could bypass Microsoft’s Natural Language Processing, which was acting as a Phishing email protection for Office users. 

Office 365 – Natural Language Processing

Microsoft has been working towards their way of securing its customers in all aspects. One of the major areas they focus on is phishing (Business Email Compromise) attacks, which have been the most used technique by threat actors for infiltrating organizations.

- Advertisement - Google News

To prevent these phishing emails, Microsoft has been relying on Natural Language Processing, which scans the contents of an email for signs of impersonation or fraud. If an email content includes text like “© 2018 Microsoft Corporation. All rights reserved” and the email is not from Microsoft.com, Microsoft immediately flags this email as fraudulent.

This technique was also used to interpret email contents like banking information, user accounts, password resets, and financial requests and are checked for authenticity. However, threat actors bypassed this technique using the ZeroFont Phishing attack.

ZeroFont Phishing

The threat actor sends an email to the victim impersonating an Office 365 quota limit notification, which looks like an administrative service email. However, this phishing email bypassed the protection due to the use of the ZeroFont attack.

ZeroFont Phishing attack (Source: AVANAN)

Threat actors inserted random text inside the email, which had <span style=”FONT-SIZE: 0px”> for a zero font size, and broke up the text strings to bypass Microsoft’s natural language processing. 

zerofont
Source: Avanan

A complete report has been published by Avanan, which provides detailed information about this attack and bypass scenarios used by threat actors. 

Protect yourself from vulnerabilities using Patch Manager Plus to quickly patch over 850 third-party applications. Take advantage of the free trial to ensure 100% security.

Eswar
Eswar
Eswar is a Cyber security content editor with a passion for creating captivating and informative content. With years of experience under his belt in Cyber Security, he is covering Cyber Security News, technology and other news.

Latest articles

Zero-Trust Policy Bypass Enables Exploitation of Vulnerabilities and Manipulation of NHI Secrets

A new project has exposed a critical attack vector that exploits protocol vulnerabilities to...

Threat Actor Sells Burger King Backup System RCE Vulnerability for $4,000

A threat actor known as #LongNight has reportedly put up for sale remote code...

Chinese Nexus Hackers Exploit Ivanti Endpoint Manager Mobile Vulnerability

Ivanti disclosed two critical vulnerabilities, identified as CVE-2025-4427 and CVE-2025-4428, affecting Ivanti Endpoint Manager...

Hackers Target macOS Users with Fake Ledger Apps to Deploy Malware

Hackers are increasingly targeting macOS users with malicious clones of Ledger Live, the popular...

Resilience at Scale

Why Application Security is Non-Negotiable

The resilience of your digital infrastructure directly impacts your ability to scale. And yet, application security remains a critical weak link for most organizations.

Application Security is no longer just a defensive play—it’s the cornerstone of cyber resilience and sustainable growth. In this webinar, Karthik Krishnamoorthy (CTO of Indusface) and Phani Deepak Akella (VP of Marketing – Indusface), will share how AI-powered application security can help organizations build resilience by

Discussion points


Protecting at internet scale using AI and behavioral-based DDoS & bot mitigation.
Autonomously discovering external assets and remediating vulnerabilities within 72 hours, enabling secure, confident scaling.
Ensuring 100% application availability through platforms architected for failure resilience.
Eliminating silos with real-time correlation between attack surface and active threats for rapid, accurate mitigation

More like this

Zero-Trust Policy Bypass Enables Exploitation of Vulnerabilities and Manipulation of NHI Secrets

A new project has exposed a critical attack vector that exploits protocol vulnerabilities to...

Threat Actor Sells Burger King Backup System RCE Vulnerability for $4,000

A threat actor known as #LongNight has reportedly put up for sale remote code...

Chinese Nexus Hackers Exploit Ivanti Endpoint Manager Mobile Vulnerability

Ivanti disclosed two critical vulnerabilities, identified as CVE-2025-4427 and CVE-2025-4428, affecting Ivanti Endpoint Manager...