How Zero-Point Fonts in Phishing Emails Make Them Look Safe

Stu Sjouwerman | Sep 28, 2023

Phishing Emails Are After CredentialsAttackers are using zero-point fonts to make phishing emails appear as though they’ve been verified by security scanners, BleepingComputer reports. While attackers have used zero-point fonts in the past to evade security filters, ISC SANS analyst Jan Kopriva found that threat actors can use these fonts to trick users as well.

“Modern email clients commonly display received email messages in a layout containing two side-by-side windows – one showing the list of received (or sent, drafted, etc.) messages and the other showing the body of a selected message,” Kopriva explains.

Kopriva found that email applications will show the beginning text of an email in the sidebar listing, even if the text is size zero. In this case, the text stated, “Scanned and secured by Isc®Advanced Threat protection (APT),” BleepingComputer notes, “The goal is to instill a false sense of legitimacy and security in the recipient. By presenting a deceptive security scan message, the likelihood of the target opening the message and engaging with its content rises.”

Kopriva adds that this technique adds another layer of legitimacy to a phishing email.

“While I wouldn’t be surprised if this technique has been used before, this was the first time I came across it,” Kopriva says. “Although it is a technique with only minor impact, it might still confuse some recipients into believing that a phishing message is trustworthy – especially if the text displayed in the “listing window” was well chosen. It is, in any case, one more small addition to the threat actor toolbox which may be used to create more effective phishing campaigns, and it is therefore certainly good for us – as defenders – to be aware of it…Furthermore, since it is currently being used ‘in the wild,’ it might not be a bad idea to mention it in any phishing-oriented security awareness courses.”

KnowBe4 enables your workforce to make smarter security decisions every day. Over 65,000 organizations worldwide trust the KnowBe4 platform to strengthen their security culture and reduce human risk.

BleepingComputer has the story.

Discover Your Organization’s Phish-prone™ Percentage

Ninety-one percent of data breaches begin with spear phishing. Launch our Free Phishing Security Test for up to 100 users to uncover your team's vulnerability and see how your security posture stacks up against industry benchmarks.

Get Your Free Phishing Security Test

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the modern workforce to make smarter security decisions every day. Trusted by more than 70,000 organizations worldwide, KnowBe4 is the pioneer of digital workforce security, securing both AI agents and humans. The KnowBe4 Platform provides attack simulation and training, collaboration security, and agent security powered by AIDA (Artificial Intelligence Defense Agents) and a proprietary Risk Score. The platform leverages 15 years of behavioral data to combat advanced threats including social engineering, prompt injection, and shadow AI. By securing humans and agents, KnowBe4 leads the industry in workforce trust and defense.