ASCII smuggling, a technique that abuses invisible Unicode characters to trick AI models, is now being used to thwart both traditional and AI-based email filters, Microsoft said in a blog post Thursday.Microsoft researchers discovered a high-volume email phishing campaign in February 2026 while conducting research on Microsoft Defender for Office 365 prompt injection protection.The team observed a sharp increase in hits on a hunting signature designed to detect ASCII smuggling prompt injections, but rather than finding hidden instructions targeting AI models, the researchers found hidden Unicode characters being used to break up keywords likely to trigger signature-based email defenses.The technique is similar to “text salting” methods seen in previous campaigns, but past examples have typically used character with a font size of zero, zero-width spaces (U+200B) or no-break spaces (U+00A0) to obfuscate keywords. In the campaign reported by Microsoft, the attacker specifically used Unicode Tags block (U+E0000 to U+E007F), which is more commonly seen in ASCII smuggling prompt injection attacks.The Unicode Tags block is frequently used to hide prompt injections as it contains “shadow copies” of printable ASCII characters that are usually not rendered but are still readable by AI models and automated systems, Microsoft explained. In this case, these invisible characters were inserted into frequently filtered keywords such as “funding” to prevent the suspicious word from being detected.Microsoft saw the frequency of this specific Unicode Tags block being used in emails skyrocket from about 5,000-20,000 emails per day to more than 1.3 million on Feb. 9, 2026. This high volume of emails containing ASCII smuggling characters continued through May 15, 2026, peaking at 2.37 million emails on Feb. 26 and keeping a consistent weekly cadence that dropped sharply on weekends and continued throughout the typical workweek, suggesting scheduled, bulk delivery.Researchers were able to tie this campaign to a known, ongoing financial lure-themed phishing operation previously identified by Fortra in September 2025. The attackers tied to this campaign abuse the legitimate email-marketing platform ActiveCampaign to send bulk emails and obscure malicious links using ActiveCampaign’s native URL-rewriting feature that routes links through click-tracking domains. “We take abuse, fraud, and security extremely seriously. We tested the specific technique described in this research against our content-moderation systems: messages containing invisible Unicode characters receive the same moderation verdicts as their unobfuscated equivalents, and heavy use of the technique is itself treated as a suspicious signal,” an ActiveCampaign spokesperson said in a statement published by Microsoft. “We continually invest in improving our detection and prevention capabilities, including expanding our use of AI and machine learning to identify abusive sending behavior earlier in the account lifecycle.”
Related Events
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
You can skip this ad in 5 seconds