Close Menu
NCIJ Network NCIJ Network
    What's Hot

    140 migrants in single dinghy rescued in English Channel

    September 6, 2026

    TechCrunch Mobility: Tesla Cybercab hits the road — and a snag

    September 6, 2026

    Aave V4 vote would grant unused emergency powers

    September 6, 2026
    Facebook X (Twitter) Instagram
    Trending
    • 140 migrants in single dinghy rescued in English Channel
    • TechCrunch Mobility: Tesla Cybercab hits the road — and a snag
    • Aave V4 vote would grant unused emergency powers
    • Compound in blueberries may help muscle cells burn excess fat
    • Why federal judge ruled First Amendment protects certain AI-generated child sex abuse material
    • Niger military accuses France of orchestrating failed mutiny: What to know | News
    • That sound you hear is not the world ending – it’s liberalism being monstered | Waleed Aly
    • Long-term allies and verifiable reality must make way for Saving Private Nige | John Crace
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Sunday, September 6
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Attackers conceal phishing lures using invisible Unicode characters

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKSeptember 6, 2026 Cybersecurity No Comments3 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Threat actors have adopted the ASCII smuggling technique in phishing campaigns, using invisible Unicode characters to evade email security filters.

    ASCII smuggling has been used in AI prompt injection attacks to conceal malicious instructions from users by encoding them with Unicode characters from the Tags block (U+E0000–U+E007F).

    Microsoft threat researchers discovered a large-scale phishing campaign using this technique, which peaked at up to 2.37 million daily messages in late February. Although the volume has dropped gradually in May, the operation is still active.

    “The high-volume phase persisted for roughly three months after February 9 and dropped sharply after May 15, 2026,” explains Microsoft.

    “These dates bound the observed use of the specific technique in our telemetry, not the broader campaign, which started earlier without it and continued without it.”

    Phishing email delivery volumes
    Phishing email delivery volumes
    Source: Microsoft

     

    In this campaign, the attacker inserts an invisible Unicode character inside finance-related lure words to split them.

    In doing so, a keyword like ‘funding’ becomes something like ‘fun[invisible character]ding’ and evades email filters that rely on word lists to detect suspicious or malicious messages.

    Sample of a phishing message
    Sample of a phishing message
    Source: Microsoft

    Microsoft says the method has been used in millions of finance-themed phishing messages and works as intended, although Defender still caught over 99% of the messages based on other signals (sender, IP, domain, reputation checks).

    On February 9, Microsoft identified a cluster of 148 finance-themed sender domains powering this campaign, accounting for about 96% of all messages its new Defender for Office 365 hunting logic flagged for Unicode-tag signatures.

    Unicode characters in the text
    Unicode characters in the email
    Source: Microsoft

    The domains used words such as “funding,” “capital,” “loan,” “advance,” and “credit,” and the messages promoted business funding, loans, and credit services.

    The messages were delivered through infrastructure associated with the legitimate ActiveCampaign email-marketing platform.

    After receiving Microsoft’s report of service abuse, ActiveCampaign said its moderation systems detect invisible Unicode characters the same way they detect unobfuscated text and treat heavy use as suspicious.

    Microsoft recommends that defenders strip or normalize Unicode tag characters and other invisible code points before applying keyword, regex, or signature-based detection, and treat unexpected tag-block characters as a strong anomaly.

    Applying the same normalization before passing email content to AI assistants should mitigate the risk of prompt-injection attacks.


    article image

    Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.

    The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.

    Get the report

    Attackers characters conceal Invisible Lures Phishing Unicode
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Attackers Hijack MikroTik Routers Through Internet-Exposed SSH Without Authentication

    Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores

    Critical VMware Workstation and Fusion Flaw Lets VM Admins Execute Host Code

    Attackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS Credentials

    Over 5,400 hacked sites serve ClickFix payloads stored on the blockchain

    Trezor Says ShipMonk Breach Exposed 67,000 U.S. Customers’ Data It Said Was Deleted

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    140 migrants in single dinghy rescued in English Channel

    September 6, 2026

    TechCrunch Mobility: Tesla Cybercab hits the road — and a snag

    September 6, 2026

    Aave V4 vote would grant unused emergency powers

    September 6, 2026

    Compound in blueberries may help muscle cells burn excess fat

    September 6, 2026
    Latest Posts

    Quantum computing nears commercial breakthrough, IBM CEO says

    August 1, 2026

    Amgen says cloud data breach exposed patient health, proprietary info

    August 1, 2026

    Snapchat joins other platforms in the fight against ‘AI slop’

    August 1, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    140 migrants in single dinghy rescued in English Channel

    September 6, 2026

    TechCrunch Mobility: Tesla Cybercab hits the road — and a snag

    September 6, 2026

    Aave V4 vote would grant unused emergency powers

    September 6, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.