1200KM / simulation
T1027.018 Invisible Unicode — Attack Simulation
Adversaries may abuse invisible or non-printing Unicode characters to conceal malicious content within files, scripts, or text. By inserting characters that do not visibly render, adversaries may hide data, alter how content is interpreted, or make malicious code appear as benign text or whitespace. Adversaries may encode these malicious payloads, using binary, Base64, or custom schemes, to be reconstructed at runtime through scripting features…
Technique description
Adversaries may abuse invisible or non-printing Unicode characters to conceal malicious content within files, scripts, or text. By inserting characters that do not visibly render, adversaries may hide data, alter how content is interpreted, or make malicious code appear as benign text or whitespace. Adversaries may encode these malicious payloads, using binary, Base64, or custom schemes, to be reconstructed at runtime through scripting features…
At least one platform-compatible Atomic procedure is documented. Individual review, lab prerequisites, and validation remain required.
Official ATT&CK definition · Detection rules and anomaly models
Documented simulation candidates
- Invisible Unicode in Environment Variables
Procedure 125b1b41-bcef-42c3-acaa-a44303e3ffc1; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Binary Masquerading via Invisible Unicode
Procedure 28e30460-ce18-4974-8e6a-5a2bb74e5c07; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- File Masquerading with Zero-Width Space
Procedure 5917f0fd-c6d4-4af8-b89d-f3db06349c49; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
Connected ecosystem references
Linked tags
Detection and collection
Attack tools
No reviewed association in this snapshot.
Existing research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.