Phishing Kit Uses Custom Font Files to Decode Text

Stu Sjouwerman | Jan 5, 2019
bpf3

Researchers discovered a phishing template that uses a unique method for encoding text using web fonts. The researchers found that the source code of the landing page contained encoded text, but the browser unexpectedly renders it as cleartext.

The page impersonates the website of a major bank. Digging deeper, the researchers traced the source of the character substitution cipher to the page’s CSS code. The code references a “fonts” folder that doesn’t exist, so instead it loads two base64-encoded woff and woff2 font files. These font files are custom-made with the letters out of order. When the browser renders the page, it treats the font as if it’s in alphabetical order and replaces the letters in the source code with readable text.

The researchers also note that the phishing kit utilizes stolen branding to impersonate the bank, but the source code doesn’t contain the logo. Rather, the images are created via scalable vector graphics (SVG), which allows the site to evade automated scanners.

The researchers’ findings show a creative way to avoid detection by security vendors. Criminals will always find ways to bypass detection mechanisms, so organizations can’t rely solely on technical safeguards to prevent attacks. New-school security awareness training can give employees up-to-date knowledge of the various methods used by attackers to stay ahead of the curve.


Find out how affordable security awareness training is for your organization. 

 
Get A Quote
 

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the modern workforce to make smarter security decisions every day. Trusted by more than 70,000 organizations worldwide, KnowBe4 is the pioneer of digital workforce security, securing both AI agents and humans. The KnowBe4 Platform provides attack simulation and training, collaboration security, and agent security powered by AIDA (Artificial Intelligence Defense Agents) and a proprietary Risk Score. The platform leverages 15 years of behavioral data to combat advanced threats including social engineering, prompt injection, and shadow AI. By securing humans and agents, KnowBe4 leads the industry in workforce trust and defense.