7 Sources
[1]
Once popular for attacking AI, ASCII smuggling is embraced by spammers
A clever technique used to hide malicious prompts in attacks on AI agents has been adopted by spammers to evade filters on email platforms that are designed to flag unwanted messages used in mass campaigns. The technique is broadly known as ASCII smuggling. It gained attention two years ago as a
[2]
ASCII smuggling isn't just an AI security risk
Fraudsters have found a new use for ASCII smuggling, typically used to hide malicious prompts intended for AI models, in an old-school attack method: email phishing. Microsoft uncovered a massive phishing campaign using invisible Unicode tag characters that peaked at more than 2.37 million
[3]
Attackers conceal phishing lures using invisible Unicode characters
Threat actors have adopted the ASCII smuggling technique in phishing campaigns, using invisible Unicode characters to evade email security filters. ASCII smuggling has been used in AI prompt injection attacks to conceal malicious instructions from users by encoding them with Unicode characters
[4]
Phishing Campaign Sends Millions of Emails Using Invisible Unicode to Evade Filters
Microsoft is alerting of a "high-volume phishing campaign" that's using invisible Unicode tag characters to bypass email filters. "Instead of using these characters to hide instructions from people while exposing them to AI models, the attacker used them to split financial lure words such as
[5]
ASCII smuggling crossed over from AI attacks to spam
Invisible Unicode characters became famous for hiding instructions from people while feeding them to AI models. Microsoft has found a phishing operation using them for something duller: splitting the word funding so filters miss it. The ASCII smuggling campaign hit 2.37 million messages a weekday,
[6]
Hackers are using 'invisible' Unicode characters to sneak phishing lures into emails
Technique used in prompt injection attacks has made it into phishing * Microsoft reports phishing campaign using ASCII smuggling to bypass spam filters * Attackers insert invisible characters into keywords, tricking filters and AI agents * Defenders should normalize Unicode tags and flag
[7]
ASCII Smuggling: How Attackers are Using Hidden Text to Bypass AI Email Security
Invisible Unicode can hide malicious keywords from security systems while leaving email content visually unchanged. Microsoft observed millions of messages, showing how quickly this technique can scale in coordinated fraud campaigns. Text normalization and layered detection are essential to
Share
Copy Link
Microsoft uncovered a large-scale phishing campaign using invisible Unicode characters to split financial keywords and evade email spam filters. The operation peaked at 2.37 million messages daily in late February 2026, adapting ASCII smuggling techniques originally designed for AI prompt injection attacks into traditional spam operations.
A massive phishing campaign leveraging ASCII smuggling techniques sent up to 2.37 million emails daily at its peak, marking a significant evolution in how cybercrime adapts AI-related security threat methods for traditional spam operations
1
. Microsoft researchers Noam Kochavi and Sarah Wolstencroft discovered the operation in early February 2026, when detection signatures for invisible Unicode characters suddenly spiked from roughly 21,000 messages on February 8 to more than 1.3 million the following day2
. The campaign maintained weekday volumes between 1 and 2.37 million messages for approximately three months before dropping sharply after May 15, 20263
.
Source: The Register
ASCII smuggling gained prominence two years ago as a method to conceal malicious instructions in AI prompt injection attacks. The technique exploits the Unicode Tags block (U+E0000-U+E007F), which contains invisible shadow copies of printable ASCII characters that computers can read but humans cannot see
4
. While originally designed for language tagging and later abandoned by Unicode, these characters became valuable for hiding prompts from users while exposing them to large language models. Attackers would embed instructions in emails or documents using tags like U+E0041 to mirror "A" and U+E0061 to mirror "a," enabling AI assistants to execute unauthorized actions without user awareness1
.The phishing campaign operated through approximately 150 finance-themed sender domains, with 148 identified on February 9 alone accounting for roughly 96% of flagged messages
3
. These domains incorporated terms like "funding," "capital," "loan," "advance," and "credit" to target small business owners seeking financial services. The top-performing sender domains included guardiangrowthfunding[.]com, digitalcapitalboost[.]com, thebusinessloanexpress[.]com, yourlocfunding[.]com, and advancefundingboost[.]com4
.
Source: Hacker News
Instead of hiding AI instructions, attackers inserted invisible Unicode tag spaces between letters to split financial keywords and evade keyword-matching filters. A word like "funding" became "fun⟨U+E0020⟩ding," appearing normal to recipients while defeating literal string matches that spam filters rely upon
2
. This approach targets both traditional detection systems and modern machine learning classifiers that tokenize text before analysis. When natural language processing systems split text into tokens or sub-word pieces, the inserted invisible character can fragment familiar tokens into rare or unknown sequences, disrupting pattern recognition1
.The operation demonstrated distinctive characteristics that revealed its automated nature. Messages followed a strict weekday-on, weekend-off schedule, with traffic collapsing to near zero every Sunday and resuming full volume on Mondays
5
. This rhythm indicates scheduled bulk-sending infrastructure rather than manual operation. After an intense first phase peaking on February 26, weekday volumes gradually declined by roughly 80% by late March before the sharp drop in mid-May2
.Messages were delivered through infrastructure associated with ActiveCampaign, a legitimate email marketing and automation platform. The broader campaign weaponized ActiveCampaign's AI-powered features to mass-produce convincing, tailored websites that adapt to different illegitimate domains, targeting Small Business Administration (SBA) loan applicants
4
. Every outbound link in message bodies was routed through ActiveCampaign's click-tracking domains. After Microsoft reported the service abuse, ActiveCampaign stated its moderation systems detect invisible Unicode characters the same way they detect unobfuscated text and treat heavy use as suspicious3
.Related Stories
Despite the campaign's scale and sophistication, Microsoft Defender for Office 365 caught over 99% of the messages based on signals unrelated to the invisible characters themselves
3
. Sender and IP reputation checks, URL and domain analysis, brand impersonation detection, authentication protocols, and machine learning classifiers all flagged the messages. Defender's approach of photographing message content and performing OCR extraction over the visual image proved particularly effective, as it sees exactly what human recipients see1
.
Source: The Next Web
The evasion technique ironically became a detection indicator. Tag characters are so rare in legitimate email that their presence now serves as a high-confidence campaign indicator
5
. Microsoft's signature had only one false-positive issue: legitimate mail containing flags of England, Scotland, and Wales, which are built from invisible tag characters. The sudden spike of tag-block characters concentrated on finance-themed senders, switching on and off weekly, provides defenders with a distinctive behavioral pattern to monitor2
.Microsoft advises defenders to verify that Unicode normalization and tokenization pipelines handle tag characters consistently. Any content evaluated by keyword, signature, or regex logic should first have invisible and non-rendering Unicode code points stripped or folded, preventing attackers from bypassing modern spam detection systems by splicing them into words
2
. This same control helps reduce threats from ASCII smuggling against AI assistants that ingest email content, addressing both traditional phishing and AI prompt injection attacks simultaneously3
.The campaign illustrates how AI-era attack methods can be adapted for use in traditional threats like phishing and spam, reinforcing the need for defenders to view emerging threats through a cross-domain lens. While spammers have used zero-width spaces and non-breaking spaces for decades to achieve similar obfuscation, the adoption of Unicode tag characters represents an attempt to bypass defenses that hadn't yet been programmed to detect them
1
. Organizations should implement behavioral monitoring for sudden spikes in tag-block usage and maintain robust multi-layered detection that doesn't rely solely on content analysis to protect against evolving spear-phishing techniques.Summarized by
Navi
[2]
[3]
[5]
14 Jul 2025•Technology

02 Jan 2025•Technology

27 Aug 2025•Technology

1
Technology

2
Technology

3
Policy and Regulation
