Close Menu
AIToday7

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    OpenAI Scientist Warns of AI Risk as GPT

    September 7, 2026

    AI Demand Drives DRAM Industry Revenue Up Nearly 60% QoQ; Samsung Holds Top Spot

    September 7, 2026

    Yes, We’re Entering the Era of Artificial General Intelligence

    September 7, 2026
    Facebook X (Twitter) Instagram
    Trending
    • OpenAI Scientist Warns of AI Risk as GPT
    • AI Demand Drives DRAM Industry Revenue Up Nearly 60% QoQ; Samsung Holds Top Spot
    • Yes, We’re Entering the Era of Artificial General Intelligence
    • Harvey + Legora on OpenAI’s GPT-6 Astra
    • Seeking emotional Support From generative AI May Signal Psychological Distress in kids: JAMA
    • 3 Things You Should Know Before Buying A Jeep Wrangler
    • AMC CEO Furious at Robinhood for Tokenizing Stock Without Permission
    • Attackers conceal phishing lures using invisible Unicode characters
    Facebook X (Twitter) Instagram Pinterest Vimeo
    AIToday7
    • Home
    • AI News
    • Tech News
    • AI Guides
    • Chatbots
    • Cybersecurity
    • Gadgets
    • More
      • Generative AI
      • Startups
    AIToday7
    Home»Cybersecurity»Attackers conceal phishing lures using invisible Unicode characters
    Cybersecurity

    Attackers conceal phishing lures using invisible Unicode characters

    aitoday7By aitoday7September 6, 2026No Comments3 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Attackers conceal phishing lures using invisible Unicode characters
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Bill Toulas

    • September 6, 2026
    • 10:23 AM

    Threat actors have adopted the ASCII smuggling technique in phishing campaigns, using invisible Unicode characters to evade email security filters.

    ASCII smuggling has been used in AI prompt injection attacks to conceal malicious instructions from users by encoding them with Unicode characters from the Tags block (U+E0000–U+E007F).

    Microsoft threat researchers discovered a large-scale phishing campaign using this technique, which peaked at up to 2.37 million daily messages in late February. Although the volume has dropped gradually in May, the operation is still active.

    “The high-volume phase persisted for roughly three months after February 9 and dropped sharply after May 15, 2026,” explains Microsoft.

    “These dates bound the observed use of the specific technique in our telemetry, not the broader campaign, which started earlier without it and continued without it.”

    Phishing email delivery volumes
    Phishing email delivery volumesSource: Microsoft

    In this campaign, the attacker inserts an invisible Unicode character inside finance-related lure words to split them.

    In doing so, a keyword like ‘funding’ becomes something like ‘fun[invisible character]ding’ and evades email filters that rely on word lists to detect suspicious or malicious messages.

    Sample of a phishing message
    Sample of a phishing messageSource: Microsoft

    Microsoft says the method has been used in millions of finance-themed phishing messages and works as intended, although Defender still caught over 99% of the messages based on other signals (sender, IP, domain, reputation checks).

    On February 9, Microsoft identified a cluster of 148 finance-themed sender domains powering this campaign, accounting for about 96% of all messages its new Defender for Office 365 hunting logic flagged for Unicode-tag signatures.

    Unicode characters in the text
    Unicode characters in the emailSource: Microsoft

    The domains used words such as “funding,” “capital,” “loan,” “advance,” and “credit,” and the messages promoted business funding, loans, and credit services.

    The messages were delivered through infrastructure associated with the legitimate ActiveCampaign email-marketing platform.

    After receiving Microsoft’s report of service abuse, ActiveCampaign said its moderation systems detect invisible Unicode characters the same way they detect unobfuscated text and treat heavy use as suspicious.

    Microsoft recommends that defenders strip or normalize Unicode tag characters and other invisible code points before applying keyword, regex, or signature-based detection, and treat unexpected tag-block characters as a strong anomaly.

    Applying the same normalization before passing email content to AI assistants should mitigate the risk of prompt-injection attacks.

    article image

    Once attackers have valid credentials, only 37% of their actions are blocked

    Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.

    The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.

    Post Views: 2

    attackers conceal lures phishing Security
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleFBI looking into driver’s license data breach possibly linked to New Orleans ID
    Next Article AMC CEO Furious at Robinhood for Tokenizing Stock Without Permission
    aitoday7
    • Website

    Related Posts

    Cybersecurity

    FBI looking into driver’s license data breach possibly linked to New Orleans ID

    September 6, 2026
    Cybersecurity

    Vexy Ransomware Strikes Sancity Soft Touch – DeXpose

    September 5, 2026
    Cybersecurity

    Vexy Ransomware Targets Annapurna Fashion – DeXpose

    September 5, 2026
    Add A Comment
    Leave A Reply Cancel Reply

    Top Posts

    OpenAI Scientist Warns of AI Risk as GPT

    September 7, 20260 Views

    AI Demand Drives DRAM Industry Revenue Up Nearly 60% QoQ; Samsung Holds Top Spot

    September 7, 20260 Views

    Yes, We’re Entering the Era of Artificial General Intelligence

    September 7, 20260 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews
    Uncategorized

    Architecting memory and storage in the AI era

    aitoday7September 4, 2026
    Uncategorized

    Roland Releases Melody Flip, an AI Melody-Generation Plug-In for DAWs

    aitoday7September 4, 2026
    Uncategorized

    Home Depot Labor Day Sale (2026): BOGO on Best Grills and Tools

    aitoday7September 4, 2026

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Most Popular

    OpenAI Scientist Warns of AI Risk as GPT

    September 7, 20260 Views

    AI Demand Drives DRAM Industry Revenue Up Nearly 60% QoQ; Samsung Holds Top Spot

    September 7, 20260 Views

    Yes, We’re Entering the Era of Artificial General Intelligence

    September 7, 20260 Views
    Our Picks

    Architecting memory and storage in the AI era

    September 4, 2026

    Roland Releases Melody Flip, an AI Melody-Generation Plug-In for DAWs

    September 4, 2026

    Home Depot Labor Day Sale (2026): BOGO on Best Grills and Tools

    September 4, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Get In Touch
    • Disclaimer
    • Privacy Policy
    • Terms and Conditions
    © 2026 AIToday7. All Rights Reserved.

    Type above and press Enter to search. Press Esc to cancel.