ASCII smuggling crosses over from AI prompt injection to phishing evasion
released on 2026-09-03 @ 05:36:50 PM
Microsoft researchers identified a high-volume phishing campaign utilizing invisible Unicode tag characters (U+E0000 to U+E007F), a technique originally associated with AI prompt injection research known as ASCII Smuggling. The attackers inserted these invisible characters into financial keywords like 'funding' to evade email filters rather than hiding instructions from users. The campaign began February 9, 2026, generating millions of daily messages for approximately three months with a distinctive weekday-only pattern. Finance-themed disposable domains were used to send business loan and credit-line phishing through a legitimate email marketing platform. The technique, while designed for AI security contexts, proved effective at bypassing traditional keyword-based detection by splitting words with invisible characters that appear normal to recipients but break signature matches and alter ML tokenization.