An innovative JavaScript obfuscation method that leverages invisible Unicode characters to represent binary values is being actively used in phishing attacks targeting affiliates of a US political action committee (PAC).
See also: New Device Code Phishing Attack Steals Authentication Tokens

Juniper Threat Labs, which detected the attack, reports that it took place in early January 2025 and is characterized by a high degree of sophistication, such as:
- Personalized non-public information for targeting victims,
- Error breakpoint and timing checks to avoid detection,
- Postmark tracking links to obscure phishing final destinations.
JavaScript developer Martin Kleppe first demonstrated the obfuscation technique in October 2024. Its rapid adoption in real-world attacks highlights how quickly innovative research can be turned into an attack tool .
The new technique leverages invisible Unicode characters, specifically the Hangul character (U+FFA0) and the Hangul character (U+3164), opening up new possibilities for data hiding. Each Unicode character in the JavaScript payload is converted to an 8-bit binary representation. The binary values (0 and 1) are then replaced with invisible Hangul characters, offering a unique and discreet approach to encoding.
See also: Phishing attacks abuse CDN and CAPTCHA
The obfuscated code is stored as a property in a JavaScript object. Because the Hangul filler characters are displayed as white space, the script content appears empty. This is evident from the white space observed at the end of the image below.

A short startup script retrieves the hidden payload via a "get()" trap from a JavaScript proxy. When the hidden property is enabled, the proxy converts the invisible Unicode Hangul filler characters to binary code and accurately reconstructs the original JavaScript code.
According to Juniper analysts, attackers are implementing additional obfuscation techniques beyond those already known. These include encoding scripts using base64 and incorporating anti-debug mechanisms to make their analysis and detection more difficult.
Attacks are difficult to detect, as the empty space significantly reduces the likelihood of being detected even by advanced security scanners, making their identification more challenging. The payload, as a simple property of an object, can be inserted into perfectly legitimate scenarios without raising suspicion. Furthermore, the coding process is easy to implement and does not require specialized knowledge or advanced know-how.
See also: Phishing attack targets Ukraine's largest bank
Phishing attacks are one of the most common and dangerous threats in cyberspace. Attackers try to trick their victims into revealing sensitive information, such as passwords or bank account details, through fraudulent emails, websites or other means of communication. It is important to remain vigilant and verify the authenticity of any communication before providing personal data.
Source: bleepingcomputer
🔑 Secure your passwords with Proton Pass
Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.
- ✔ Encrypted storage of passwords & passkeys
- ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
- ✔ Free version — on all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
