As cited
Copy frozen at (site build).
threat intel
ASCII smuggling crosses over from AI prompt injection to phishing evasion
Microsoft researchers detected a high-volume phishing campaign from February through May 2026 that repurposed ASCII smuggling, a technique from artificial intelligence (AI) security research, to evade email filters rather than hide instructions from people. The attackers inserted invisible Unicode tag characters into financial keywords like 'funding' to break signature matching and disrupt tokenization in machine learning (ML) models. The campaign sent millions of business loan and advance-funding phishing emails daily from disposable finance-themed domains through the ActiveCampaign marketing platform, maintaining a strict weekday-on, weekend-off schedule.
Why it matters: Email security teams must verify that their content normalization and tokenization pipelines strip or normalize Unicode tag characters (U+E0000-U+E007F) before applying spam and phishing signatures, since ML-based classifiers that do not handle these invisible characters consistently become vulnerable to this evasion tactic.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
threat intel
ASCII smuggling crosses over from AI prompt injection to phishing evasion
Microsoft researchers detected a high-volume phishing campaign from February through May 2026 that repurposed ASCII smuggling, a technique from artificial intelligence (AI) security research, to evade email filters rather than hide instructions from people. The attackers inserted invisible Unicode tag characters into financial keywords like 'funding' to break signature matching and disrupt tokenization in machine learning (ML) models. The campaign sent millions of business loan and advance-funding phishing emails daily from disposable finance-themed domains through the ActiveCampaign marketing platform, maintaining a strict weekday-on, weekend-off schedule.
Why it matters: Email security teams must verify that their content normalization and tokenization pipelines strip or normalize Unicode tag characters (U+E0000-U+E007F) before applying spam and phishing signatures, since ML-based classifiers that do not handle these invisible characters consistently become vulnerable to this evasion tactic.
- Source published
- First seen by Cybersecurity Tracker