
New Red Team Tactic 'Evil Fonts' Exploits Custom Fonts for Malicious Attacks
cybersecurityred_teamexploitmalwarewindowsphishingfont_manipulation
The post describes a technique called 'Evil Fonts,' which manipulates fonts to display misleading text to users while storing different, potentially malicious commands on disk. This tactic can bypass security tools in Windows corporate networks, enable initial access via click-based attacks, and create traps for harvesting shells. The method works in HTML, DOCX, PDFs, and other formats where custom fonts can be embedded. Demonstrations and labs are provided via a GitHub repository.