{"success":true,"data":{"id":"hangul-filler-invisible-javascript-payload","label":"Hangul-filler binary payload — 16+ consecutive U+FFA0 / U+3164 runs encoding invisible JS (Tycoon 2FA PhaaS technique)","description":"HTML body contains 16+ consecutive U+FFA0 (Halfwidth Hangul Filler) or U+3164 (Hangul Filler) characters — a steganographic technique that encodes JavaScript as a binary string over the two codepoints. Both render as invisible whitespace in every major browser. Pioneered by Martin Kleppe (Oct 2024), first observed in the wild by Juniper Threat Labs in January 2025, and adopted into the Tycoon 2FA PhaaS kit in April 2025 (LevelBlue SpiderLabs + SocRadar). Distinct from existing `body-invisible-char-obfuscation` which fires on zero-width chars INTERLEAVED between Latin letters — this fires on pure consecutive runs. Legitimate Korean email uses composed Hangul syllables (U+AC00-U+D7A3) and Jamo (U+1100-U+11FF), never the standalone fillers.","tier":"danger","category":"other","isThin":false}}