Remember invisible ink? It was a clever way to hide secret messages as children. Cybercriminals have now adopted a digital version of the same idea, concealing malicious content inside phishing emails to evade detection and increase the chances of reaching your inbox.
What Is Zero-Font Phishing and Why It Matters Today?
As email security technology becomes more effective, attackers are increasingly turning to techniques designed to confuse detection engines without altering what recipients see. Zero-font phishing is one of the latest examples. Anti-spam / phishing filters work in several different ways; they look for specific words or phrases and there is then a statistical element. If there are 100,000 instances of the same message, it’s probably spam. For phishing, protection technology will look for words like ‘bank’, ‘account’, ‘change’, ‘update’ and where the email seems to have come from (e.g., is the address spoofed?). Are there URL’s which point to known cybercrime sites? All this information comes together to create a score and therefore an action. However, in a bid to beat the protection which is deployed, new techniques are used, or old ones are resurrected with a new twist. Zero font is just one of those.
The idea is relatively simple… “what you see is not what you get.” Email messages are composed using HTML, and in between the actual message are other characters, but with a font size of zero. From an analysis side, the text is there, but when it’s displayed, it isn’t as it is in effect hidden. The cyber-criminals use this to break up words which would otherwise be caught by the filters. So, “account” could become “actually count”, with the “tually “ being in a zero point font. This can also be used in URLs, in fact, any text. Cyber-criminals can then change the ‘hidden’ words so that no two emails are the same.
Why Zero-Font Phishing Is Effective
Zero-font phishing exploits a fundamental challenge in email security: the difference between what a machine analyzes and what a person sees. By inserting hidden text within email content, attackers can break up suspicious words, alter URLs, and create countless variations of the same message. This helps bypass traditional filtering techniques that rely on pattern matching, keyword detection, or the identification of duplicate messages. The result is a phishing email that appears legitimate to the recipient while looking significantly different to a security scanner. In short, Zero-Font Phishing can:
- Disrupt keyword-based filtering.
- Help attackers create unique email variants.
- Enable phishing messages to bypass traditional pattern matching.
- Be combined with other evasion techniques, such as URL masking and HTML manipulation.
How Organizations Can Defend Against Zero-Font Phishing
Of course, as new methods to beat the protection systems come out, so to do new methods to defeat the new methods. Organizations should use layered email security that goes beyond simple keyword detection, including:
- Machine learning and behavioral analysis
- Advanced HTML inspection
- URL reputation analysis
- Sender authentication technologies (SPF, DKIM, DMARC)
- User awareness training