CSEC Research // Own Hardware Only

Zero-Width Unicode Steganographic Payload Delivery
Technique Steganography Target PowerShell VirusTotal 0 / 72 Status Active Research
01 // Terminal Demo
The Ghost in the Shell

A ghost-encoded file looks completely blank in any text editor. cat it in PowerShell and the console spits back ??????? because no font can render zero-width Unicode characters. But execute that same file and the payload runs clean.

PowerShell — ghost_demo
02 // Visual Comparison
Normal vs Ghost

Same payload. Same execution result. One is readable, one is invisible.

normal_script.ps1 — 247 bytes
# Standard PowerShell script
$target = $env:COMPUTERNAME
$user = $env:USERNAME
$ts = Get-Date -Format "yyyy-MM-dd HH:mm"
 
Write-Host "[+] Host: $target"
Write-Host "[+] User: $user"
Write-Host "[+] Time: $ts"
Write-Host "[GHOST] Payload executed."
ghost_encoded.ps1 — 1,482 bytes
[ file appears completely blank ]
zero-width Unicode chars are invisible in all standard text rendering
PS> cat ghost_encoded.ps1
???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????
03 // Mechanism
How It Works
01
16 Invisible Characters

A 16-character alphabet of zero-width Unicode code points. Each character is invisible in standard rendering — no glyph, no width, no visible presence. Text editors show nothing. Hex editors reveal the truth.

02
Hex Encoding

Each payload byte splits into two nibbles. High nibble maps to one ghost character, low nibble to another. Byte 0x48 ('H') becomes ghost char at index 4 + ghost char at index 8. Two invisible characters per byte.

03
In-Memory Execution

A minimal visible decoder stub reads the ghost data, reconstructs ASCII bytes, and feeds the result to Invoke-Expression. Payload never exists as a readable file on disk. Executes entirely in memory.

Ghost Alphabet — 16 Zero-Width Characters
Idx Code Point Unicode Name Idx Code Point Unicode Name
0x0 U+200B Zero Width Space 0x8 U+2063 Invisible Separator
0x1 U+200C Zero Width Non-Joiner 0x9 U+2064 Invisible Plus
0x2 U+200D Zero Width Joiner 0xA U+2065 Reserved [invisible]
0x3 U+200E Left-to-Right Mark 0xB U+2066 LR Isolate
0x4 U+200F Right-to-Left Mark 0xC U+2067 RL Isolate
0x5 U+2060 Word Joiner 0xD U+2068 First Strong Isolate
0x6 U+2061 Function Application 0xE U+2069 Pop Directional Isolate
0x7 U+2062 Invisible Times 0xF U+180E Mongolian Vowel Separator
Encoding Example — Byte 0x48 ('H')

Input byte: 0x48
High nibble: 0x4 → ghost[4] = U+200F (Right-to-Left Mark)
Low nibble: 0x8 → ghost[8] = U+2063 (Invisible Separator)

One ASCII byte → two invisible Unicode characters.
100-byte payload → 200 ghost characters. Zero visible content.

04 // Detection Profile
What Sees It, What Doesn't
Layer Detects Ghost? Notes
Text Editor (Notepad, VS Code) NO File appears completely blank — zero rendered glyphs
PowerShell cat Shows ??????? Console font can't render zero-width chars — substitutes fallback glyph
Windows Defender (static) NO No signature match on Unicode noise — content is not recognizable as code
VirusTotal NO 0/72 engine detections — no scanner flags zero-width Unicode as malicious
AMSI (runtime) MAYBE Scans decoded payload at Invoke-Expression — needs dark_room to blind
ETW Logging YES Logs the PowerShell command pipeline — needs dark_room to suppress
Kaspersky KSN (cloud) PARTIAL KSN submits unknown carrier file hash on first run — 0/72 is Defender-era. Novel ghost files have no KSN reputation. Cloud engine can flag anomalous Unicode density independently of content.
Kaspersky System Watcher POST-EXEC RISK Behavioral rollback engine (bRollbackAllowed=1 confirmed on lab). Does not block delivery or execution — but can undo file writes, registry changes, and persistence vectors if heuristic fires after the fact. AMSI/ETW bypass does not neutralise System Watcher.
Summary

Ghost encoding defeats all static analysis. The file is invisible to human review and opaque to signature-based scanning. Against Windows Defender, the chain is complete: ghost delivery + dark_room AMSI/ETW bypass = disk-to-execution undetectable.

Against Kaspersky Premium (tested: 21.25.7.504, KSN enabled), two gaps remain. First: KSN cloud lookup sees the carrier file hash on first execution — novel files with no KSN reputation trigger cloud analysis even when static and AMSI scans pass. Second: System Watcher is a rollback engine, not a blocker. It can fire post-execution and undo persistence writes (registry Run, scheduled task, startup LNK) independent of whether AMSI and ETW were blinded. Neutralising System Watcher requires either disabling it via the Kaspersky UI, operating within an excluded path, or avoiding disk writes entirely (fileless persistence only).

STATUS: Defender — VERIFIED CLEAN. Kaspersky — UNDER TEST. System Watcher bypass: PENDING.

05 // Integration
Where Ghost Lives

Ghost encoding is not a standalone tool. It functions as a steganographic layer that other tools in the arsenal chain through.

05

Operational Build Plan

How the 22-module curriculum is constructed, tested on live lab machines, and deployed. No simulations. Real code, real AV, real defenses.

PHASE 1 — SKELETON
Build automation pipeline + 3 core modules

Widget Generator (Python template engine) → Reader Generator (iframe embed) → POC Tester (SSH to lab machines) → Git Push & Verify (automated deploy). Target modules: 12 (ETW Bypass), 13 (KAV Evasion), 14 (Cloud Files).

PHASE 2 — BULK FILL
Fill remaining gaps + Track B (Blue Team)

Modules 03, 04, 06, 07, 09, 10, 15, 17, 18, 20, 22. Track B: Blue Team Fundamentals, Detection Engineering, Incident Response, Threat Hunting, Deception Technology.

PHASE 3 — POLISH
Mobile responsive, cross-browser, performance, SEO

Payment gate integration only after all content verified live. No product = no sale.

LAB MATRIX
.92 Intel (Kaspersky ON) | .42 AMD (Clean sandbox) | .145 RADON (Authorized target)

Every POC tested on at least one live machine before widget built. Real output embedded, not invented.

KSN CAVEAT
Ghost beats static signatures, not cloud reputation

Zero-width Unicode bypasses static AV — file appears as noise. But Kaspersky KSN performs cloud hash lookup on first execution. If carrier is novel, KSN submits for behavioral analysis. Combine ghost with Dark Room (HWBP ETW bypass) for runtime evasion. Test on live Kaspersky before claiming FUD.

22nd Survey Division Course Portal →