Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Farage seeks to shore up damaged leadership as scandal engulfs Reform conference | Nigel Farage

    September 4, 2026

    France downplays SpaceX, Blue Origin snub of ‘worst Macron-organized’ summit – POLITICO

    September 4, 2026

    ‘I can’t be bought,’ Nige tells Reform’s faithful – however different it may look | John Crace

    September 4, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Farage seeks to shore up damaged leadership as scandal engulfs Reform conference | Nigel Farage
    • France downplays SpaceX, Blue Origin snub of ‘worst Macron-organized’ summit – POLITICO
    • ‘I can’t be bought,’ Nige tells Reform’s faithful – however different it may look | John Crace
    • Judge blocks X rival from using Twitter name, but allows ‘Tweet’ for now
    • Phishing Campaign Sends Millions of Emails Using Invisible Unicode to Evade Filters
    • Crypto Biz: Bitcoin rally revives miners as Strategy, Strive buy more BTC
    • NASA Hosts Virtual Artemis Webinar for Blind, Low-Vision Community
    • Marine conservation collides with mining in Indonesia’s biodiversity-rich Moramo Bay
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Friday, September 4
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Phishing Campaign Sends Millions of Emails Using Invisible Unicode to Evade Filters

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKSeptember 4, 2026 Cybersecurity No Comments5 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Microsoft is alerting of a “high-volume phishing campaign” that’s using invisible Unicode tag characters to bypass email filters.

    “Instead of using these characters to hide instructions from people while exposing them to AI models, the attacker used them to split financial lure words such as ‘funding’ to prevent email filters from parsing them,” the Microsoft Security Research team said.

    The Windows maker said the findings show AI-era evasion techniques can be adapted by threat actors in traditional phishing and spam campaigns. Attacks exploiting this approach are said to have first emerged in early February 2026.

    ASCII Smuggling refers to a technique where invisible or non-rendering Unicode characters are used to conceal messages or instructions inside seemingly-harmless text. As a result, human user interfaces do not render them, making the text appear completely normal to the user.

    However, such content can be ingested by email filters or AI language models, mistakenly treating it as real text. This, in turn, can open the door to prompt injection by taking advantage of the fact that large language models (LLMs) cannot draw a reliable boundary between genuine user instructions entered directly into a prompt and content embedded into benign-looking text or other third-party sources such as web pages, documents, or emails.

    Cybersecurity

    “The most abused range is the Unicode Tags block, U+E0000 to U+E007F,” Microsoft said. “This block contains a shadow copy of the printable ASCII characters (for example, U+E0041 mirrors ‘A,’ U+E0061 mirrors ‘a’). The block was originally intended for language tagging and is now largely deprecated.”

    According to the Windows maker, the ASCII smuggling-oriented phishing campaign entered into a high-volume phase for roughly three months before dropping sharply post May 15, 2026. The activity is said to have followed a weekly cadence, with the campaign almost going radio silent on weekends and resuming in full swing on Mondays.

    Weekday volumes are estimated to reach anywhere between 1 to 2.37 million messages, hitting a peak on February 26, 2026. The campaign is assessed to be tied to a broader phishing campaign that weaponized the ActiveCampaign marketing and automation platform to distribute thousands of AI-generated phishing emails targeting Small Business Administration (SBA) loan applicants.

    Details of the phishing campaign were disclosed by the Fortra Intelligence and Research Experts (FIRE) team in September 2025, stating the operation focuses on collecting detailed business and financial information, likely to enable highly targeted spear‑phishing in future attacks.

    “The campaign’s sophistication and uniqueness lies in the ability to mass‑produce convincing, tailored websites that adapt to different illegitimate or impersonated domains,” Fortra noted at the time. “Threat actors are able to scale sophisticated phishing by using ActiveCampaign’s AI-powered marketing automation features to vary the design, content, and flow, ultimately creating more convincing phishing campaigns, quicker.”

    The latest set of phishing emails, per Microsoft, leverages the invisible tag characters as an obfuscation pattern, inserting them inside common financial keywords so as to split them apart and get around email filters looking for keyword or literal signature matches.

    For instance, a finance-related lure term such as “funding” becomes “fun⟨U+E0020⟩ding,” so that it looks normal to the email recipient while having the side effect of bypassing email security controls.

    “To a recipient, and to parsing pipelines that drop or normalize these characters, the word still reads as funding,” Microsoft explained. “To a detector matching the literal string funding, or a regex that does not account for interleaved invisible code points, the byte sequence no longer contains the contiguous keyword.”

    While the use of invisible or look-alike characters is not a new technique in phishing and homoglyph attacks, what’s novel is the choice of the characters used – namely, the Unicode Tags block – and the scale of the campaign itself, which has generated multi-million messages on a daily basis.

    Cybersecurity

    The campaign has been found to leverage hundreds of disposable, finance-themed sender domains using lures that mimicked business loan, line-of-credit, and advance-funding phishing patterns that are typically associated with fraud or credential-harvesting schemes. The top 10 sender domains by the most hits are listed below –

    • guardiangrowthfunding[.]com
    • digitalcapitalboost[.]com
    • thebusinessloanexpress[.]com
    • yourlocfunding[.]com
    • advancefundingboost[.]com
    • guardiancapitalway[.]com
    • harboradvancefunding[.]com
    • unitedfundingwave[.]com
    • directcapitalboost[.]com
    • onlinedirectfinance[.]com

    What’s more, these emails from these finance-themed domains are relayed through ActiveCampaign, causing every outbound link in the message body to be routed via its own click-tracking domains (“acemlnd[.]com” and “activehosted[.]com”).

    ActiveCampaign, for its part, said it has tested its content-moderation systems with messages containing invisible Unicode characters, and that such emails receive the moderation verdict as their unobfuscated equivalents. It also said a heavy use of the technique is treated as a “suspicious signal.”

    “As with any shared sending service, attacker abuse of customer accounts or workflows can complicate reputation-based filtering,” Microsoft said. “By originating from a reputable marketing platform with established IP reputation and authentication, the activity may appear more similar to legitimate marketing traffic and can complicate reputation-based filtering.”

    campaign Emails Evade Filters Invisible millions Phishing Sends Unicode
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    The democratization of cyber warfare — and what it means for CISOs

    Critical Citrix NetScaler auth bypass now leveraged in attacks

    Microsoft says some users can’t open the Teams desktop client

    Sangoma Switchvox Vulnerabilities Exploited in the Wild

    Google Releases Chrome Update to Patch Actively Exploited V8 Zero-Day

    Google warns of new Chrome zero-day flaw exploited in attacks

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Farage seeks to shore up damaged leadership as scandal engulfs Reform conference | Nigel Farage

    September 4, 2026

    France downplays SpaceX, Blue Origin snub of ‘worst Macron-organized’ summit – POLITICO

    September 4, 2026

    ‘I can’t be bought,’ Nige tells Reform’s faithful – however different it may look | John Crace

    September 4, 2026

    Judge blocks X rival from using Twitter name, but allows ‘Tweet’ for now

    September 4, 2026
    Latest Posts

    Interpol Leverages Global System to Curtail Fraud Payments

    July 31, 2026

    Repeat founder Ryan Williams raises $10M seed for an AI startup for private credit managers

    July 31, 2026

    Concerns raised over Northumberland council’s £900m debt

    July 31, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Farage seeks to shore up damaged leadership as scandal engulfs Reform conference | Nigel Farage

    September 4, 2026

    France downplays SpaceX, Blue Origin snub of ‘worst Macron-organized’ summit – POLITICO

    September 4, 2026

    ‘I can’t be bought,’ Nige tells Reform’s faithful – however different it may look | John Crace

    September 4, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.