[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fgWqmznxSC1m1-8El95hse0IU7Ce78lp0GJAQfLX6bZ4":3},{"article":4,"iocs":49},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":31,"category":32,"article_tags":36},"ac28e317-f337-42bb-a48b-79cfccf0f877","Phishing Campaign Sends Millions of Emails Using Invisible Unicode to Evade Filters","phishing-campaign-sends-millions-of-emails-using-invisible-unicode-to-evade-filt-ffe72a","Microsoft is alerting of a \"high-volume phishing campaign\" that's using invisible Unicode tag characters to bypass email filters. \"Instead of using these characters to hide instructions from people while exposing them to AI models, the attacker used them to split financial lure words such as 'funding' to prevent email filters from parsing them,\" the Microsoft Security Research team said. The","A high-volume phishing campaign is using invisible Unicode tag characters to split financial lure words, evading email filters. This technique, known as ASCII smuggling, was observed in millions of emails between February and May 2026, often targeting SBA loan applicants with AI-generated phishing content distributed via ActiveCampaign.","Phishing campaign uses invisible Unicode characters to bypass email filters.","Phishing Campaign Sends Millions of Emails Using Invisible Unicode to Evade Filters Ravie LakshmananSep 04, 2026Email Security \u002F Artificial Intelligence Microsoft is alerting of a \"high-volume phishing campaign\" that's using invisible Unicode tag characters to bypass email filters. \"Instead of using these characters to hide instructions from people while exposing them to AI models, the attacker used them to split financial lure words such as 'funding' to prevent email filters from parsing them,\" the Microsoft Security Research team said. The Windows maker said the findings show AI-era evasion techniques can be adapted by threat actors in traditional phishing and spam campaigns. Attacks exploiting this approach are said to have first emerged in early February 2026. ASCII Smuggling refers to a technique where invisible or non-rendering Unicode characters are used to conceal messages or instructions inside seemingly-harmless text. As a result, human user interfaces do not render them, making the text appear completely normal to the user. However, such content can be ingested by email filters or AI language models, mistakenly treating it as real text. This, in turn, can open the door to prompt injection by taking advantage of the fact that large language models (LLMs) cannot draw a reliable boundary between genuine user instructions entered directly into a prompt and content embedded into benign-looking text or other third-party sources such as web pages, documents, or emails. \"The most abused range is the Unicode Tags block, U+E0000 to U+E007F,\" Microsoft said. \"This block contains a shadow copy of the printable ASCII characters (for example, U+E0041 mirrors 'A,' U+E0061 mirrors 'a'). The block was originally intended for language tagging and is now largely deprecated.\" According to the Windows maker, the ASCII smuggling-oriented phishing campaign entered into a high-volume phase for roughly three months before dropping sharply post May 15, 2026. The activity is said to have followed a weekly cadence, with the campaign almost going radio silent on weekends and resuming in full swing on Mondays. Weekday volumes are estimated to reach anywhere between 1 to 2.37 million messages, hitting a peak on February 26, 2026. The campaign is assessed to be tied to a broader phishing campaign that weaponized the ActiveCampaign marketing and automation platform to distribute thousands of AI-generated phishing emails targeting Small Business Administration (SBA) loan applicants. Details of the phishing campaign were disclosed by the Fortra Intelligence and Research Experts (FIRE) team in September 2025, stating the operation focuses on collecting detailed business and financial information, likely to enable highly targeted spear‑phishing in future attacks. \"The campaign's sophistication and uniqueness lies in the ability to mass‑produce convincing, tailored websites that adapt to different illegitimate or impersonated domains,\" Fortra noted at the time. \"Threat actors are able to scale sophisticated phishing by using ActiveCampaign's AI-powered marketing automation features to vary the design, content, and flow, ultimately creating more convincing phishing campaigns, quicker.\" The latest set of phishing emails, per Microsoft, leverages the invisible tag characters as an obfuscation pattern, inserting them inside common financial keywords so as to split them apart and get around email filters looking for keyword or literal signature matches. For instance, a finance-related lure term such as \"funding\" becomes \"fun⟨U+E0020⟩ding,\" so that it looks normal to the email recipient while having the side effect of bypassing email security controls. \"To a recipient, and to parsing pipelines that drop or normalize these characters, the word still reads as funding,\" Microsoft explained. \"To a detector matching the literal string funding, or a regex that does not account for interleaved invisible code points, the byte sequence no longer contains the contiguous keyword.\" While the use of invisible or look-alike characters is not a new technique in phishing and homoglyph attacks, what's novel is the choice of the characters used – namely, the Unicode Tags block – and the scale of the campaign itself, which has generated multi-million messages on a daily basis. The campaign has been found to leverage hundreds of disposable, finance-themed sender domains using lures that mimicked business loan, line-of-credit, and advance-funding phishing patterns that are typically associated with fraud or credential-harvesting schemes. The top 10 sender domains by the most hits are listed below - guardiangrowthfunding[.]com digitalcapitalboost[.]com thebusinessloanexpress[.]com yourlocfunding[.]com advancefundingboost[.]com guardiancapitalway[.]com harboradvancefunding[.]com unitedfundingwave[.]com directcapitalboost[.]com onlinedirectfinance[.]com What's more, these emails from these finance-themed domains are relayed through ActiveCampaign, causing every outbound link in the message body to be routed via its own click-tracking domains (\"acemlnd[.]com\" and \"activehosted[.]com\"). ActiveCampaign, for its part, said it has tested its content-moderation systems with messages containing invisible Unicode characters, and that such emails receive the moderation verdict as their unobfuscated equivalents. It also said a heavy use of the technique is treated as a \"suspicious signal.\" \"As with any shared sending service, attacker abuse of customer accounts or workflows can complicate reputation-based filtering,\" Microsoft said. \"By originating from a reputable marketing platform with established IP reputation and authentication, the activity may appear more similar to legitimate marketing traffic and can complicate reputation-based filtering.\" Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post. SHARE     Tweet Share Share Share SHARE  artificial intelligence, Cybercrime, email security, Phishing, Social Engineering ⚡ Top Stories This Week Critical Keycloak Password Reset Flaw Could Let Unauthenticated Attackers Take Over Any Account ⚡ Weekly Recap: AI-Powered PLC Attacks, GitLab Attacks, Stripe Key Leaks and More Actively Exploited Oracle WebLogic Flaw Lets Unauthenticated Attackers Access Critical Data WhatsApp Adds Multiple Passkeys for Phishing-Resistant Sign-Ins Across iOS and Android A Malicious Webpage Could Poison Your Local AI Model Behind NVIDIA NemoClaw Critical Gitea RCE Actively Exploited as Reported Attack Drops Miner-Like Payload Claude Opus 4.6 Bypasses Gym Booking Limit, Cancels Other Users' Reservations in Tests CISA Red Team Compromised Two Critical Infrastructure Orgs, One Detected Nothing FBI Disrupts China-Linked QTFY Infrastructure Used to Steal Data From U.S. Organizations New GPUThor Rowhammer Defeats ECC on NVIDIA RTX A6000 to Gain Host Root Access Alleged TeamPCP Hackers Charged in Australia Over Major Supply Chain Attacks ThreatsDay: 296K IoT Botnet, 100+ Water Systems Targeted, SharePoint RCE Chain + 27 New Stories Next.js Patches Critical AVIF and Windows Flaws Enabling Unauthenticated RCE OpenAI Says Reward Hacking Drove AI Agents to Exploit Zero-Days and Breach Hugging Face Critical cPanel Flaw Could Let One Hosting Customer Take Root Control of a Whole Server PaperCut Zero-Day Exploited in Attacks, Affecting All NG and MF Versions Three CVSS 10.0 ServiceNow Flaws Could Let Unauthenticated Attackers Execute Code and SQL Attackers Chain Two PaperCut Flaws to Execute Code Without Authentication Learn How to Build Security Operations Ready for AI-Powered Attacks Imagine the SOC Without a Queue: From Alert Backlog to AI Hypothesis Engine Mirage2FA Surge Hits 4,500 US and EU Companies, Abusing Microsoft 365 Login Flows Frontier AI: Vulnerability Management's Systemic Revolution Why AI Teams Need Verifiable Search Data Instead of Black-Box Signals Why Threat Intelligence Needs OT Context to Protect Critical ","https:\u002F\u002Fthehackernews.com\u002F2026\u002F09\u002Fphishing-campaign-sends-millions-of.html","https:\u002F\u002Fblogger.googleusercontent.com\u002Fimg\u002Fb\u002FR29vZ2xl\u002FAVvXsEjoD4eMYuhLT8HvcHbYe8A4hkhmDH1f4pIWTIm5AXKueqdpY1NS8yNiTtlzS4mdIS8PLY8_zM1uQDNpO1U49HCUoJT8nn2Bpb6krpcYpOSQ3H3Z6fUsm-UkoFvj8fk8oShK0eUhO6px8hox_ZzlnX8tu0pJKpJ3UAF2Vcb3XyBXjCt_8uD8OOkMMgUjv8Pc\u002Fs1600\u002Femails.jpg","2026-09-04T15:57:15+00:00","2026-09-04T18:00:24.891733+00:00",8,[18,21,24,27,29],{"name":19,"type":20},"ActiveCampaign","product",{"name":22,"type":23},"Microsoft","vendor",{"name":25,"type":26},"Unicode","technology",{"name":28,"type":26},"AI",{"name":30,"type":26},"ASCII smuggling","e7b231c8-5f79-4465-8d38-1ef13aea5a14",{"id":31,"icon":33,"name":34,"slug":35},null,"Threat Intelligence","threat-intelligence",[37,42,47],{"category":38},{"id":39,"icon":33,"name":40,"slug":41},"839da5c1-3c34-47e2-9499-f7201640e3ac","AI Security","ai-security",{"category":43},{"id":44,"icon":33,"name":45,"slug":46},"89f78b1c-3503-45a1-9fc7-e23d2ce1c6d5","Malware","malware",{"category":48},{"id":31,"icon":33,"name":34,"slug":35},[50,54,57],{"type":51,"value":52,"context":53},"mitre_attack","T1041","Exfiltration Over C2 Channel (used for ASCII smuggling to bypass filters)",{"type":51,"value":55,"context":56},"T1566.002","Phishing: Spearphishing Attachment (implied by targeting loan applicants)",{"type":51,"value":58,"context":59},"T1566.001","Phishing: Spearphishing Link (implied by distributing via ActiveCampaign)"]