hacker-news · Crawled Sep 4, 2026

Phishing Campaign Sends Millions of Emails Using Invisible Unicode to Evade Filters

12 IoCs
Read original article ↗

AI Summary

A high-volume phishing campaign has been leveraging invisible Unicode tag characters, specifically from the Unicode Tags block (U+E0000 to U+E007F), to obfuscate financial lure words such as 'funding' and evade email security filters. The technique, known as ASCII Smuggling, splits keywords with non-rendering characters (e.g., 'fun⟨U+E0020⟩ding') to bypass literal string detection while appearing normal to human recipients. The campaign has sent millions of emails daily, primarily targeting Small Business Administration (SBA) loan applicants, using the ActiveCampaign platform to distribute AI-generated phishing emails and dynamically generated, convincing phishing websites. The operation uses disposable finance-themed domains and leverages ActiveCampaign's infrastructure for link tracking, complicating reputation-based filtering.

AI-extracted · verify before operational use

Indicators of Compromise 12 extracted

Type Value Detail
Domain guardiangrowthfunding[.]com Details →
Domain digitalcapitalboost[.]com Details →
Domain thebusinessloanexpress[.]com Details →
Domain yourlocfunding[.]com Details →
Domain advancefundingboost[.]com Details →
Domain guardiancapitalway[.]com Details →
Domain harboradvancefunding[.]com Details →
Domain unitedfundingwave[.]com Details →
Domain directcapitalboost[.]com Details →
Domain onlinedirectfinance[.]com Details →
Domain acemlnd[.]com Details →
Domain activehosted[.]com Details →