Full Report
Attackers are using the "ZeroFont" technique to manipulate the preview of a message to suggest it had already been scanned for threats. Read more in my article in the Tripwire State of Security blog.
Analysis Summary
# Tool/Technique: ZeroFont (Phishing Evasion)
## Overview
ZeroFont is an email obfuscation technique where attackers insert text into an HTML email with a font size of zero. This makes the text invisible to the human eye when reading the email body but allows it to be processed by email clients for message previews (snippets). Its primary purpose is to deceive users by presenting a fake "security scan" status in the preview pane while hiding the actual malicious content of the email until it is opened.
## Technical Details
- **Type:** Phishing / Evasion Technique
- **Platform:** Cross-platform (Email clients such as Microsoft Outlook, Gmail, and Apple Mail)
- **Capabilities:** Preview manipulation, bypass of simple NLP-based filters, social engineering.
- **First Seen:** Approximately 2018 (General use); specific variant for "Scanned by Security" previews noted in 2023-2024.
## MITRE ATT&CK Mapping
- **TA0001 - Initial Access**
- **T1566.001 - Phishing: Spearphishing Attachment**
- **T1566.002 - Phishing: Spearphishing Link**
- **TA0005 - Defense Evasion**
- **T1564 - Hide Artifacts**
- **T1027 - Obfuscated Files or Information**
## Functionality
### Core Capabilities
- **Preview Manipulation:** By placing ZeroFont text at the very beginning of the HTML body, attackers ensure this text is what the email client pulls for the "Message Preview" in the inbox list.
- **Social Engineering:** The technique is used to display strings like "Scanned and secured by [Security Vendor]" to instill a false sense of trust before the user even opens the mail.
### Advanced Features
- **Filter Evasion:** By interleaving zero-font characters or words between malicious keywords, attackers can break up strings that automated security scanners look for, effectively "breaking" simple keyword detection.
## Indicators of Compromise
- **File Hashes:** N/A (Technique-based)
- **File Names:** N/A
- **Registry Keys:** N/A
- **Network Indicators:** Often associated with credential harvesting domains (e.g., hxxps[://]legit-looking-domain[.]com/login).
- **Behavioral Indicators:**
- Discrepancy between the message snippet in the inbox view and the actual content of the email.
- Presence of HTML tags such as `<span style="font-size:0px;">` or `<div style="display:none;">` (though `display:none` is a separate but related technique).
## Associated Threat Actors
- **Generic Phishing Operations:** Widely adopted by various cybercriminal groups for credential theft.
- **Advanced Persistent Threats (APTs):** Various groups have been known to use HTML obfuscation to bypass secure email gateways (SEGs).
## Detection Methods
- **Signature-based detection:** Scanning for specific HTML CSS properties where `font-size` is set to `0`, `0px`, or `hidden`.
- **Behavioral detection:** Analyzing the delta between the plain-text extraction of an email and the rendered view provided to the user.
- **YARA Rule Concept:**
yara
rule ZeroFont_Detection {
strings:
$s1 = "font-size:0px" nocase
$s2 = "font-size:0" nocase
$s3 = "display:none" nocase
condition:
any of them
}
## Mitigation Strategies
- **Prevention measures:** Implement Secure Email Gateways (SEGs) that perform "visual rendering" analysis rather than just text-based scraping.
- **Hardening recommendations:**
- Disable message previews in email clients for high-risk users.
- Standardize internal communication so users know what legitimate security headers look like.
- **User Education:** Train employees to recognize that security scan notifications are typically part of the email header or a banner added by the gateway, not the first line of the message body.
## Related Tools/Techniques
- **Quishing:** (QR Code Phishing) - Another method to hide malicious URLs from scanners.
- **Character Substitution/Homoglyphs:** Using look-alike characters to bypass filters.
- **Hidden Text/White-on-White:** Setting font color to match the background to hide content from humans but not from machines.