Home ยท Wiki ยท Incidents & Campaigns
type: incident ยท created: 2026-09-07 ยท updated: 2026-09-07 ยท tags: [incident, phishing, evasion, unicode, campaign] ยท confidence: high ยท affected_sectors: [finance, technology] ยท au_impact: true

Attackers Conceal Phishing Lures Using Invisible Unicode Characters

Microsoft threat researchers described a large-scale phishing campaign using the ASCII-smuggling technique, in which invisible Unicode characters from the Tags block (U+E0000โ€“U+E007F) are inserted inside finance-related lure words (such as "funding") to split them and evade email security filters while remaining visually intact.

Attribute Detail
Technique ASCII smuggling (invisible Unicode U+E0000โ€“U+E007F)
Peak volume Up to 2.37 million messages/day (late February 2026)
Duration ~3 months; dropped sharply after 15 May 2026, still active
Source Microsoft (via BleepingComputer) โ€” Tier 2/4

The technique is already established in AI prompt-injection attacks for concealing malicious instructions; its adoption in consumer phishing signals attackers porting evasion mechanics across threat classes. Users are advised to examine sender identity and links in finance-related email regardless of how natural the message appears.

Source