bleeping-computer · Crawled Sep 6, 2026

Attackers conceal phishing lures using invisible Unicode characters

Read original article ↗

AI Summary

Threat actors are using a technique called ASCII smuggling, inserting invisible Unicode characters (from the Tags block U+E0000–U+E007F) into finance-related keywords in phishing emails to evade detection by email security filters. Microsoft observed a large-scale campaign peaking at 2.37 million messages per day, primarily using sender domains associated with the ActiveCampaign email platform. The obfuscation splits words like 'funding' into 'fun[Unicode]ding' to bypass keyword-based detection, though most messages were still caught by other signals such as sender reputation. Microsoft recommends normalizing or stripping invisible Unicode characters to defend against this tactic in both email filtering and AI prompt processing.

AI-extracted · verify before operational use

No entities or IoCs were extracted from this article.