Cybercriminals have developed a sophisticated phishing technique that exploits invisible characters embedded in email subject lines to bypass automatic security filters.
See also: New phishing campaign targets LastPass users

This attack method leverages MIME encoding in combination with Unicode soft hyphens to conceal malicious intent while appearing legitimate to human readers. The technique represents an evolution in social engineering tactics, targeting email filtering mechanisms that rely on keyword detection and pattern matching.
The attack emerged when security researchers discovered phishing emails with subject lines that exhibited unusual behavior in email clients. When displayed in the message list, the subject line appeared garbled or incomplete, but when the email was opened, the text appeared as normal, readable content. This discrepancy indicated the presence of invisible characters strategically placed throughout the subject line to disrupt recognizable keywords and patterns.
The campaign primarily targets credential theft via fake webmail login pages. Victims receive emails with subject lines such as “Your Password Is About to Expire,” where invisible characters break up these keywords that would normally alert security systems. The phishing emails direct recipients to compromised domains that host generic credential harvesting portals designed to capture login information.
See also: Evolution of phishing attacks to bypass defenses

Analysts at the Internet Storm Center discovered this technique while reviewing malicious emails delivered to their operators' inboxes. The discovery highlighted a relatively unusual implementation of obfuscation with invisible characters, particularly within email subject lines and not just in the message bodies.
Attackers implement this technique through the MIME encoded word format as specified in RFC 2047. The subject line structure follows the pattern encoded-word = “=?” charset “?” encoding “?” encoded-text , where the content is UTF-8 character data encoded in Base64 format.
Analysis of the recorded samples revealed topic headers formatted as:
Subject: =?UTF-8?B?WcKtb3XCrXIgUMKtYXPCrXN3wq1vwq1yZCBpwq=?UTF-8?B?dMKtbyBFwq14wq1wwq1pcsKtZQ==?=
When decoded, the strings contain soft hyphen (Unicode U+00AD, HTML entity ) inserted between individual letters. These characters remain invisible to most email clients, including Outlook, effectively breaking keywords like "password" into "password" at the code level, while appearing normally to users.
See also: Phishing campaign misuses LastPass name – Company denies breach

The technique extends beyond subject lines into the message bodies, where soft hyphens break up entire words to fool content crawlers. The recorded phishing URLs led to compromised legitimate domains that hosted credential-stealing pages formatted as generic webmail login interfaces.
🔑 Secure your passwords with Proton Pass
Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.
- ✔ Encrypted storage of passwords & passkeys
- ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
- ✔ Free version — on all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
