A new but ancient technique for Phishing emails has been recently identified called ZeroFont Phishing. Threat actors have followed several tactics for sending phishing emails, bypassing all the security mechanisms.
However, using this technique, threat actors could bypass Microsoft’s Natural Language Processing, which was acting as a Phishing email protection for Office users.
Microsoft has been working towards their way of securing its customers in all aspects. One of the major areas they focus on is phishing (Business Email Compromise) attacks, which have been the most used technique by threat actors for infiltrating organizations.
To prevent these phishing emails, Microsoft has been relying on Natural Language Processing, which scans the contents of an email for signs of impersonation or fraud. If an email content includes text like “© 2018 Microsoft Corporation. All rights reserved” and the email is not from Microsoft.com, Microsoft immediately flags this email as fraudulent.
This technique was also used to interpret email contents like banking information, user accounts, password resets, and financial requests and are checked for authenticity. However, threat actors bypassed this technique using the ZeroFont Phishing attack.
The threat actor sends an email to the victim impersonating an Office 365 quota limit notification, which looks like an administrative service email. However, this phishing email bypassed the protection due to the use of the ZeroFont attack.
Threat actors inserted random text inside the email, which had <span style=”FONT-SIZE: 0px”> for a zero font size, and broke up the text strings to bypass Microsoft’s natural language processing.
A complete report has been published by Avanan, which provides detailed information about this attack and bypass scenarios used by threat actors.
Protect yourself from vulnerabilities using Patch Manager Plus to quickly patch over 850 third-party applications. Take advantage of the free trial to ensure 100% security.
Hackers prefer phishing as it exploits human vulnerabilities rather than technical flaws which make it a highly effective and low-cost…
A very important message from the Norwegian National Cyber Security Centre (NCSC) says that Secure Socket Layer/Transport Layer Security (SSL/TLS)…
Linux is widely used in numerous servers, cloud infrastructure, and Internet of Things devices, which makes it an attractive target…
ViperSoftX malware, known for stealing cryptocurrency information, now leverages Tesseract, an open-source OCR engine, to target infected systems, which extracts…
Santander has confirmed that there was a major data breach that affected its workers and customers in Spain, Uruguay, and…
The U.S. government has offered a prize of up to $5 million for information that leads to the arrest and…