Invisible Characters, SIM Swap Jail Time, and a $10 Million Bounty: This Week's Security Briefing

Three stories worth your attention: a trick that hides malicious text from spam filters, a phone-hijacking criminal who is now behind bars, and a US government reward for help catching an Iranian hacking official.

ThreatVectr Newsdesk· 3 min read
Photoreal news-editorial style, 16:9 framing, full-frame edge-to-edge composition
Share

Key points

  • Attackers are hiding malicious text inside emails using invisible Unicode characters, allowing phishing messages to slip past automated filters undetected.
  • The US government is offering a $10 million reward for information leading to an Iranian cyber official with alleged ties to state-sponsored hacking campaigns.
  • A SIM swapper, meaning a criminal who tricks phone carriers into transferring a victim's number to a device the criminal controls, has been sentenced in the United States.
  • Researchers at security firm Glasswing have published findings on the Chinese hacking group known as QTFY, including evidence of military connections.

What is the invisible-character trick, and should ordinary people worry?

Yes, a little. Researchers have documented an attack method, sometimes called InjectEave, where criminals hide instructions inside emails using invisible Unicode characters. Unicode is the global system that assigns a code to every letter, symbol, and punctuation mark across every language. Some of those codes produce characters that are completely invisible on screen.

The practical effect is unsettling. A spam filter reads the email, sees what looks like harmless text, and waves it through. The actual payload, meaning the malicious content, sits hidden in gaps the filter never examines. Your inbox gets the whole thing. You see only the innocent-looking surface.

MFA, meaning multi-factor authentication, where you confirm your identity with a second step such as a code sent to your phone, would not block a phishing email from arriving. It would, however, limit the damage if you were tricked into handing over your password, since the criminal would still need that second factor.

If you receive an unexpected email urging you to click a link or log in somewhere, go directly to the website by typing its address yourself rather than clicking.

Who is the SIM swapper, and what did they do?

A court in the United States has sentenced a SIM swapper. SIM swapping works like this: a criminal contacts your mobile carrier, pretends to be you, and convinces the carrier to move your phone number onto a SIM card the criminal owns. From that moment, your calls and text messages, including the one-time login codes banks and apps send you, go to the criminal instead.

This case is a reminder that SMS-based two-factor authentication, where a code arrives by text message, is genuinely weaker than app-based alternatives like an authenticator app, which generates codes locally on your own device and cannot be intercepted by a SIM swap.

What is the $10 million bounty about?

The US government has put up a $10 million reward for information about an Iranian official allegedly connected to state-backed hacking operations. Bounties at this scale, run through the State Department's Rewards for Justice programme, are typically aimed at disrupting groups that target critical infrastructure such as hospitals, utilities, and government systems. SecurityWeek reported on this alongside the QTFY group findings, which linked the Chinese hacking operation to military structures, adding institutional weight to what had previously looked like criminal-for-hire activity.

Story Key detail
InjectEave phishing trick Invisible Unicode characters hide malicious content from spam filters
SIM swap sentencing Criminal convicted for hijacking phone numbers to steal login codes
Iranian cyber bounty US offers $10 million for information on named official
QTFY group findings Chinese hacking group linked to military connections by Glasswing researchers
© 2026 Threat Vectr