Attackers Conceal Phishing Lures With Invisible Unicode Characters
Microsoft threat researchers described a large-scale phishing campaign using the ASCII-smuggling technique, in which invisible Unicode characters from the Tags block (U+E0000โU+E007F) are inserted inside finance-related lure words such as 'funding' to split them and evade email security filters while remaining visually intact.
Summary
Microsoft's telemetry shows the high-volume phase peaked at up to 2.37 million messages a day in late February 2026, persisted for roughly three months and dropped sharply after 15 May, though the campaign remains active. The technique is already established in AI prompt-injection attacks for concealing malicious instructions; its adoption in consumer phishing signals attackers porting evasion mechanics across threat classes. Users are encouraged to examine sender identity and links in finance-related email regardless of how natural the message appears.
Impact
- Email security filters bypassed via invisible characters that split known-lure keywords
- Large-scale delivery of finance-related phishing across consumer inboxes
- Technique crossover from AI prompt-injection to conventional phishing evasion
Sector
Financial Services
Sources
- BleepingComputer โ Attackers conceal phishing lures using invisible Unicode characters
- raw/digests/Cyber-Digest-2026-09-07.md