Suspicious Unicode character detected in email
Synopsis
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Day
Required Data
Microsoft 365 Emails
Detection Modules
Detector Tags
Evasion, Phishing
ATT&CK Tactic
Stealth (TA0005)
ATT&CK Technique
Masquerading (T1036), Social Engineering: Impersonation (T1684.001)
Severity
Informational
Description
Unicode characters can be used for obfuscation, allowing malicious actors to disguise harmful intent, URLs or attachments By embedding non-printing Unicode characters, attackers can bypass security filters and evade detection mechanisms Such characters may also be used for phishing attempts that appear legitimate to both users and security systems.
Attacker's Goals
Embedding suspicious Unicode characters in the email to appear legitimate, evade security filters and bypass detection mechanisms.
Investigative actions
Check the email address for any unusual spellings, missing letters, or unknown domains.
If the message contains attachments or links, scrutinize them for any suspicious indications.
Monitor further actions taken, such as file downloads or access to potentially malicious links.
Variations
Was this helpful?
