Attackers hide phishing lures using invisible Unicode characters

Attackers hide phishing lures using invisible Unicode characters

Attackers hide phishing lures using invisible Unicode characters

Threat actors have adopted the ASCII smuggling technique in phishing campaigns and used invisible Unicode characters to bypass email security filters.

ASCII smuggling has been used in AI prompt injection attacks to hide malicious instructions from users by encoding them with Unicode characters from the Tags block (U+E0000–U+E007F).

Microsoft threat researchers used this technique to uncover a large-scale phishing campaign that peaked in late February with up to 2.37 million daily messages. Although volumes have gradually decreased in May, operations are still active.

“The high volume period lasted for about three months after February 9th and declined sharply after May 15th, 2026.” explains Microsoft.

“This data narrowed down the observed use of the specific technique in our telemetry, not the broader campaign that began earlier and continued without it.”

Delivery volume of phishing emails
Delivery volume of phishing emails
Source: Microsoft

In this campaign, the attacker inserts an invisible Unicode character into finance-related decoy words to break them down.

A keyword like “financing” becomes something like “funny thing (invisible character).‘ and bypasses word list-based email filters to detect suspicious or malicious messages.

Example of a phishing message
Example of a phishing message
Source: Microsoft

According to Microsoft, the method was used in millions of financial-themed phishing messages and worked as intended, although Defender still intercepted over 99% of messages based on other signals (sender, IP, domain, reputation checks).

On February 9, Microsoft identified a group of 148 financial-themed sender domains driving this campaign, accounting for approximately 96% of all messages flagged for Unicode tag signatures by Defender for Office 365’s new search logic.

Unicode characters in text
Unicode characters in the email
Source: Microsoft

The domains used words such as “financing,” “capital,” “loan,” “advance,” and “credit,” and the messages promoted business financing, loans, and credit services.

The messages were delivered through the infrastructure connected to the legitimate email marketing platform ActiveCampaign.

After receiving Microsoft’s report of service abuse, ActiveCampaign said its moderation systems detect invisible Unicode characters in the same way they detect unobfuscated text, and treat heavy usage as suspicious.

Microsoft recommends that defenders remove or normalize Unicode tag characters and other invisible code points before applying keyword, regex, or signature-based detection, and to treat unexpected tag block characters as a strong anomaly.

Applying the same normalization before passing email content to AI assistants should reduce the risk of prompt injection attacks.


Item image

Overall prevention scores can hide what happens after the first access. Once attackers use valid credentials, prevention drops sharply.

The 2026 Blue Report measures defense technology for technology in 338 million simulations conducted in customer production environments.

Get the report

Leave a Reply

Your email address will not be published. Required fields are marked *