Attackers conceal phishing lures using invisible Unicode characters
Read original article ↗AI Summary
Threat actors are using a technique called ASCII smuggling, inserting invisible Unicode characters (from the Tags block U+E0000–U+E007F) into finance-related keywords in phishing emails to evade detection by email security filters. Microsoft observed a large-scale campaign peaking at 2.37 million messages per day, primarily using sender domains associated with the ActiveCampaign email platform. The obfuscation splits words like 'funding' into 'fun[Unicode]ding' to bypass keyword-based detection, though most messages were still caught by other signals such as sender reputation. Microsoft recommends normalizing or stripping invisible Unicode characters to defend against this tactic in both email filtering and AI prompt processing.
AI-extracted · verify before operational use
No entities or IoCs were extracted from this article.