DEFCON: New Red Team Tactic
EvilFontTool is a font-based deception technique that uses specially crafted fonts to display different text to human readers than what is actually stored in the document's machine-readable text. This allows attackers to manipulate documents such as HTML, DOCX, and PDFs to bypass security tools, evade AI content filters, and perform social engineering or red team operations. The technique can be used to poison help desk documentation, bypass email filters, and create traps within corporate networks. Demonstrations show how commands that appear benign to a user can actually execute malicious actions when copied and pasted.
AI Analysis
Technical Summary
EvilFontTool leverages 'evil fonts' that remap glyphs so that the visible text differs from the underlying text data. This discrepancy enables attackers to craft documents that appear safe or benign to human viewers and security tools that inspect text on disk, while actually containing malicious commands or content. The tool supports multiple formats including HTML, DOCX, and PDF, and can be used for pastejacking without JavaScript, AI filter evasion, and document poisoning. The technique is demonstrated with examples such as tampering homework, poisoning help desk documents, and bypassing AI resume filters. The underlying method exploits font rendering to deceive both users and automated security systems.
Potential Impact
This technique can be used to bypass security tooling that relies on inspecting machine-readable text, enabling attackers to deliver malicious commands or content that appear benign. It facilitates initial access in corporate networks, evades AI content filters, and allows attackers to plant traps or poison documentation. The deception can lead to execution of unintended commands by users copying and pasting text, potentially causing data loss or system compromise. However, no active exploits in the wild are reported at this time.
Mitigation Recommendations
No official patches or vendor advisories are available as this is a novel red team tactic rather than a software vulnerability. Mitigation involves awareness and detection strategies such as verifying text integrity by copying content into plain text editors to reveal discrepancies, disabling or restricting custom font usage in sensitive environments, and enhancing security tools to detect font-based text manipulation. Organizations should educate users about the risks of copying and pasting commands from untrusted documents and consider implementing controls on document handling and font usage.
DEFCON: New Red Team Tactic
Description
EvilFontTool is a font-based deception technique that uses specially crafted fonts to display different text to human readers than what is actually stored in the document's machine-readable text. This allows attackers to manipulate documents such as HTML, DOCX, and PDFs to bypass security tools, evade AI content filters, and perform social engineering or red team operations. The technique can be used to poison help desk documentation, bypass email filters, and create traps within corporate networks. Demonstrations show how commands that appear benign to a user can actually execute malicious actions when copied and pasted.
Reddit Discussion
Evil Fonts deceive a viewer by rendering a different letter than is actually on the disk. Evil Fonts can poison HTML, DOCX, PDFs, and anywhere else you can bring your own fonts. Works great in Windows corporate networks for bypassing security tooling, initial access through JavaScript free click fix (beats mitm web security tooling), and leaving traps around the network to harvest shells.
Imagine thinking you are copying whoami but what is actually on the disk is rm -rf \~
Demos:
(Use desktop)
https://doctoreww.github.io/EvilFontTool/
For the demos, copy and paste the HTML/DOCX to a notepad to remove the evil fonts. For the AI ones imagine your security tooling inspects the benign text on disk, but shows the obviously malicious extortion to the user.
Labs:
https://github.com/DoctorEww/EvilFontTool/blob/main/labs%2FREADME.md
Lab Walkthrough:
https://github.com/DoctorEww/EvilFontTool/blob/main/labs%2Fwalkthrough.md
Some evil font uses:
Tamper homework to make it so students poison AI queries
Poison help desk documentation
Bypass email filters
Clickfix
Beat resume AI filters
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
EvilFontTool leverages 'evil fonts' that remap glyphs so that the visible text differs from the underlying text data. This discrepancy enables attackers to craft documents that appear safe or benign to human viewers and security tools that inspect text on disk, while actually containing malicious commands or content. The tool supports multiple formats including HTML, DOCX, and PDF, and can be used for pastejacking without JavaScript, AI filter evasion, and document poisoning. The technique is demonstrated with examples such as tampering homework, poisoning help desk documents, and bypassing AI resume filters. The underlying method exploits font rendering to deceive both users and automated security systems.
Potential Impact
This technique can be used to bypass security tooling that relies on inspecting machine-readable text, enabling attackers to deliver malicious commands or content that appear benign. It facilitates initial access in corporate networks, evades AI content filters, and allows attackers to plant traps or poison documentation. The deception can lead to execution of unintended commands by users copying and pasting text, potentially causing data loss or system compromise. However, no active exploits in the wild are reported at this time.
Defensive Guidance
No official patches or vendor advisories are available as this is a novel red team tactic rather than a software vulnerability. Mitigation involves awareness and detection strategies such as verifying text integrity by copying content into plain text editors to reveal discrepancies, disabling or restricting custom font usage in sensitive environments, and enhancing security tools to detect font-based text manipulation. Organizations should educate users about the risks of copying and pasting commands from untrusted documents and consider implementing controls on document handling and font usage.
Technical Details
- Source Type
- Subreddit
- netsec
- Reddit Score
- 0
- Discussion Level
- minimal
- Content Source
- reddit_link_post
- Post Type
- link
- Domain
- null
- Newsworthiness Assessment
- {"score":27,"reasons":["external_link","established_author","very_recent"],"isNewsworthy":true,"foundNewsworthy":[],"foundNonNewsworthy":[]}
- Has External Source
- true
- Trusted Domain
- false
Threat ID: 6a78015abf8831d539fd46cc
Added to database: 08/09/2026, 04:26:02 UTC
Last enriched: 08/09/2026, 04:26:12 UTC
Last updated: 08/09/2026, 09:11:08 UTC
Views: 7
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.