Email security

ASCII smuggling challenges email phishing filters, Microsoft warns

ASCII smuggling, a technique that abuses invisible Unicode characters to trick AI models, is now being used to thwart both traditional and AI-based email filters, Microsoft said in a blog post Thursday.

Microsoft researchers discovered a high-volume email phishing campaign in February 2026 while conducting research on Microsoft Defender for Office 365 prompt injection protection.

The team observed a sharp increase in hits on a hunting signature designed to detect ASCII smuggling prompt injections, but rather than finding hidden instructions targeting AI models, the researchers found hidden Unicode characters being used to break up keywords likely to trigger signature-based email defenses.

The technique is similar to “text salting” methods seen in previous campaigns, but past examples have typically used character with a font size of zero, zero-width spaces (U+200B) or no-break spaces (U+00A0) to obfuscate keywords. In the campaign reported by Microsoft, the attacker specifically used Unicode Tags block (U+E0000 to U+E007F), which is more commonly seen in ASCII smuggling prompt injection attacks.

The Unicode Tags block is frequently used to hide prompt injections as it contains “shadow copies” of printable ASCII characters that are usually not rendered but are still readable by AI models and automated systems, Microsoft explained. In this case, these invisible characters were inserted into frequently filtered keywords such as “funding” to prevent the suspicious word from being detected.

Microsoft saw the frequency of this specific Unicode Tags block being used in emails skyrocket from about 5,000-20,000 emails per day to more than 1.3 million on Feb. 9, 2026. This high volume of emails containing ASCII smuggling characters continued through May 15, 2026, peaking at 2.37 million emails on Feb. 26 and keeping a consistent weekly cadence that dropped sharply on weekends and continued throughout the typical workweek, suggesting scheduled, bulk delivery.

Researchers were able to tie this campaign to a known, ongoing financial lure-themed phishing operation previously identified by Fortra in September 2025. The attackers tied to this campaign abuse the legitimate email-marketing platform ActiveCampaign to send bulk emails and obscure malicious links using ActiveCampaign’s native URL-rewriting feature that routes links through click-tracking domains.  

“We take abuse, fraud, and security extremely seriously. We tested the specific technique described in this research against our content-moderation systems: messages containing invisible Unicode characters receive the same moderation verdicts as their unobfuscated equivalents, and heavy use of the technique is itself treated as a suspicious signal,” an ActiveCampaign spokesperson said in a statement published by Microsoft. “We continually invest in improving our detection and prevention capabilities, including expanding our use of AI and machine learning to identify abusive sending behavior earlier in the account lifecycle.”

How to combat ASCII smuggling and associated phishing campaigns

While the ASCII smuggling activity Microsoft observed from February to May eventually died down, the research team offered recommendations to combat similar attacks in the future, as well as how to detect the underlying phishing operation that is expected to continue with new techniques.

First, the researchers noted that the use of characters from the Unicode Tag block U+E0000-U+E007F itself is a high-confidence indicator of abuse, as these characters are rarely used outside of a handful of specific exceptions. Microsoft noted that their most common legitimate use is to encode the flag emojis for England, Scotland and Wales, which involves specific combinations characters that can be easily excluded from filters.

To prevent keywords that have these Unicode tags inserted from slipping by email filters, Microsoft recommends stripping or normalizing characters from this specific Unicode block — along with other zero-width and invisible characters such as U+200B and U+00A0 — prior to applying content signatures.

The researchers emphasized that this technique can also disrupt large language model (LLM)-based email scanners, causing tokenizers to separate keywords before the LLM can reason over them and recognize the suspicious signatures. Normalization prior to LLM analysis or using a system that performs Optical Character Recognition (OCR) on a visual image of the email, can prevent these keywords from being missed.

The financial lure-themed phishing operation, which existed prior to the ASCII smuggling campaign and is expected to continue targeting businesses, can be detected based on a recognizable pattern of finance-themed domains and the misuse of ActiveCampaign for bulk sending.

Microsoft noted that the 20 most active sender domains identified in the campaign all used some combination of 28 specific words, including “advance,” “boost,” “business,” “capital,” “catalyst,” “choice,” “digital” and “direct” (example: digitalcapitalboost[.]com).

Additionally, most of the emails contained links to the tracking domains activehosted[.]com and acemlnd[.]com due to ActiveCampaign’s link rewriting, about 98.5% used an envelope-shaping pattern consistent with ActiveCampaign’s shared sending pool (acems<number>[.]com or emsd<number>[.]com) and 92% came from the network block 173[.]236[.]20[.]0/24. However, because these signs are tied to the legitimate ActiveCampaign platform rather than a specific threat group, they should be used to corroborate other signals and not be taken alone as signs of malicious activity, Microsoft noted.   

Laura French

Laura French has been a staff reporter for SC Media since 2023. Laura writes daily news stories, contributes to feature stories, covers industry events and edits briefs for the SC Media website. A New Jersey native, Laura graduated from Ramapo College in 2016 and has previously written for Labcompare, FireRescue1, EMS1 and Forensic Magazine.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds