A filename can look like an Excel spreadsheet while the file underneath is an executable. In the CLOUD#REVERSER campaign, attackers combined a hidden Unicode direction-control character with scripts staged on Google Drive and Dropbox, using familiar cloud services to make a malicious download less conspicuous. The same campaign shows why a trusted service domain is not proof that a file or link is safe.
How the CLOUD#REVERSER attack worked
Securonix researchers Den Iuzvyk, Tim Peck, and Oleg Kolesnikov described a campaign that started with a phishing email carrying a ZIP archive. Inside, an executable was made to resemble a Microsoft Excel file. Its name used Unicode U+202E, the right-to-left override character, so the displayed filename appeared as “RFQ-101432620247flexe.xlsx” even though the file was executable. A visible extension is only text in a filename; it does not change the file’s underlying type.
After execution, the file dropped eight payloads, including a decoy spreadsheet and obfuscated VBScript. It also created scheduled tasks disguised as Chrome updates. The VBScript launched PowerShell, which contacted attacker-controlled Google Drive and Dropbox accounts to retrieve additional scripts and binaries. The spreadsheet could distract the person who opened the attachment while the other components worked in the background.
Securonix characterized the use of Google Drive and Dropbox for file uploads and downloads as command-and-control-like activity. In other words, the services provided a place to stage and exchange files, not evidence that Google or Dropbox themselves were compromised. The reporting does not establish the campaign’s victim count or overall scale; Securonix said it could not provide target or scale information while its investigation continued.
#1 Best Overall
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
What the Unicode right-to-left override does
U+202E is a directional formatting character. It can make text that follows it display in right-to-left order, even in a filename otherwise read left to right. Attackers can use that rendering behavior to make an executable’s displayed name resemble a document filename. The trick targets what a person sees; it does not convert an executable into a spreadsheet.
That is different from a second Unicode technique Microsoft calls “ASCII smuggling.” In its 2026 reporting, Microsoft described invisible or non-rendering Unicode characters used to conceal content within text that appears ordinary. The campaign it analyzed inserted Unicode Tags characters in the U+E0000–U+E007F range, especially U+E0020, into phishing keywords. These characters can interfere with checks that look for literal keywords or patterns if the checks do not normalize or inspect the text consistently.
Rank #2
- POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
Why attackers use Google Drive, Dropbox, and other cloud services
Google Cloud’s H2 2025 threat report says attackers have used Google Drive, Microsoft SharePoint, Dropbox, and GitHub to host decoy documents and malicious files. A familiar domain can seem less suspicious to a recipient, and basic email filters or firewalls may allow traffic to well-known services. That familiarity does not make every file hosted there safe: attackers can use their own accounts or content hosted on a legitimate platform.
A cloud-hosted file can also fit into an attack after the initial email has been opened. Decoy content may occupy the user while scripts conduct reconnaissance, establish persistence, exploit systems, execute malware, or exfiltrate data. Google’s Threat Analysis Group has separately documented benign-looking PDFs hosted on OneDrive that contained phishing links, and attackers encoding payloads and commands in Google Drive filenames. Google said it disrupted the filename-based technique in that operation.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Rank #3
- POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
What Microsoft’s ASCII-smuggling figures do—and do not—show
Microsoft reported that its 2026 ASCII-smuggling campaign reached multi-million-message daily volume at its peak. In two measured weeks, approximately 98.5% of messages matched the campaign’s envelope pattern, and approximately 99.8% matched either the envelope or tracking-URL pattern. About 92% originated from one /24 network block; roughly 96% of flagged volume came from finance-themed sender domains.
Those numbers describe Microsoft’s telemetry for that campaign, not phishing as a whole and not the CLOUD#REVERSER operation. They should not be read as estimates of the share of all phishing that uses invisible Unicode or cloud storage.
Rank #4
- POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
How to reduce the risk
Train users to check the file, not just the familiar domain
Regular security-awareness training should cover misleading filenames, unexpected ZIP attachments, and cloud links that arrive without a convincing business reason. Users should verify unusual requests through a separate trusted channel and avoid treating an Excel-looking name or a Google Drive or Dropbox link as proof of safety.
Inspect files and links before they reach the endpoint
Google Cloud recommends inspecting inbound files and using URL sandboxing or URL rewriting. These controls can help expose malicious destinations or attachments before a user opens them. Coverage matters: a filter that checks only the email’s text, or a sandbox that does not inspect the eventual downloaded file, may miss later stages of an attack.
The Tool Desk
Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Best Value
- Security Key : Protect your online accounts against unauthorized access by using FIDO2 and U2F authentication with T110. It's the world's most protective security key that works with windows, Mac OS, Linux as well as Chrome, Firefox, Edge and many other major browsers.
- Certified with the new FIDO2 standard, T110 provides the benefit of fast login and strong protection against phishing, account takeover as well as many other online attactks.
- Works with : Bank of America, Github, Google, Microsoft, DUO, Twitter, Facebook, Dropbox, Apple, ebay, BINANCE, mor and more.
- Fits USB-A port : Insert the T110 security key into the USB-A port of each service and log in conveniently with one touch
- For the driver download and user guide, please visit TrustKey Solutions Home support page.
Normalize Unicode before keyword and pattern checks
Microsoft’s practical rule is “normalize before you match.” Security systems should strip or normalize invisible code points before applying keyword, signature, or regular-expression checks, and treat unusual Unicode tags as an anomaly signal. Normalization addresses hidden characters in text; file-type inspection is still needed to catch a disguised executable.
Monitor endpoint behavior and cloud-storage access
Google Cloud recommends endpoint detection for document readers that spawn PowerShell or cmd.exe, monitoring uncommon processes that connect to cloud storage, and using YARA-L rules for event-based detections. In the CLOUD#REVERSER chain, the scheduled tasks disguised as Chrome updates and the path from VBScript to PowerShell were useful behavioral signals: monitoring process relationships and persistence can reveal activity even when the download comes from a familiar cloud service.
How defensive controls complement one another
| Control | What it can catch | What to verify |
|---|---|---|
| Unicode normalization and anomaly detection | Invisible characters that can evade literal keyword or pattern matching. | Whether normalization happens before keyword, signature, and regex checks, and whether unusual Unicode is logged or flagged. |
| Inbound file inspection and URL sandboxing or rewriting | Suspicious attachments, destinations, or downloaded content before execution. | Whether ZIP contents and the final download are inspected, and whether sandbox findings reach the mail or security team. |
| Cloud-storage visibility | Unusual downloads, sharing, or connections to storage services that may be part of an attack chain. | Whether the organization can distinguish expected business use from uncommon process-to-cloud connections and review the resulting logs. |
| Endpoint detection and process monitoring | Document readers or scripts launching PowerShell or cmd.exe, suspicious scheduled tasks, and related execution behavior. | Whether process-tree alerts include parent-child relationships and can be correlated with persistence and network events. |
No single row replaces the others. Unicode normalization helps text-based detection, but it will not establish whether a file is executable. A file or URL sandbox may identify a malicious download, while endpoint monitoring can expose what runs if preventive controls miss it. Cloud activity needs context because legitimate organizations also use these services. Microsoft said an ActiveCampaign spokesperson welcomed collaboration with the security community to combat the ASCII-smuggling activity.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.
Free tools Windows power users keep installed
One-click scans. No signup required.

