
Executive Summary
Microsoft researchers recently disclosed a large-scale phishing campaign leveraging invisible Unicode characters to bypass traditional email security controls. The technique, referred to as ASCII Smuggling or Unicode Obfuscation, inserts non-rendering Unicode characters into phishing lure words such as “funding,” “credit,” “capital,” and “loan.” To users, the text appears completely normal. However, email filters, keyword-based detections, regular expressions, and some machine learning pipelines may fail to recognize the modified words.
Microsoft observed the campaign reaching up to 2.37 million phishing emails per day during its peak in February 2026. The operation used about 148 finance-themed domains and legitimate marketing infrastructure, including ActiveCampaign, to distribute malicious content.
This campaign demonstrates how threat actors are adapting techniques originally developed for AI prompt injection attacks and repurposing them for traditional phishing operations. Organizations relying heavily on keyword detection, content signatures, or pattern matching are particularly susceptible to this evasion method.
Threat Overview
| Attribute | Details |
| Threat Type | Phishing / Email Evasion |
| Technique | Unicode Obfuscation / ASCII Smuggling |
| Primary Objective | Deliver phishing content while evading email filters |
| Initial Access | |
| Affected Platforms | Microsoft 365, Google Workspace, Secure Email Gateways |
| Targeting | Business finance organizations, SMBs, loan applicants |
| Scale Observed | Up to 2.37 million emails/day |
| Infrastructure | Finance-themed domains, marketing automation services |
| Impact | Credential theft, financial fraud, business email compromise (BEC) |
Technical Analysis
How the Attack Works
Most email filtering technologies inspect message content for suspicious strings including:
- funding
- loan
- credit
- advance
- capital
- payment
- invoice
- wire transfer
Attackers insert invisible Unicode characters between letters:
Normal Word
funding
Unicode Obfuscated
fun<U+E0064>tag-character<…>ding
To the recipient, both appear identical. To many filtering engines:
fun ding
or
fun[hidden_unicode]ding
which bypasses exact-match keyword inspections.
Unicode Tags Block Abuse
The primary Unicode range abused is:
U+E0000 – U+E007F
Known as the Unicode Tags Block.
Characteristics:
- Non-printable
- Not rendered in common user interfaces
- Originally intended for language tagging
- Largely deprecated
- Can encode ASCII-equivalent characters invisibly
Microsoft identified this as the most commonly abused Unicode range within the campaign.
Example
A phishing email promoting fraudulent SBA funding opportunities may contain:
Visible text:
Small Business Funding Available
Underlying encoded text:
Small Business Fun<tag>ding Available
A user sees:
Small Business Funding Available
A filter looking for the keyword “funding” may fail to match the pattern.
Campaign Observations
Microsoft telemetry identified:
- Peak activity on February 26, 2026
- Approximately 148 finance-themed sender domains
- Activity concentrated during weekdays
- Significant reduction on weekends
- Roughly three-month period of large-scale activity
- Continued lower-volume activity after May 2026
The phishing lures predominantly focused on:
- Business funding
- SBA loans
- Credit services
- Capital advances
- Financial assistance programs
MITRE ATT&CK Mapping
| ATT&CK ID | Technique |
| T1566.001 | Phishing: Spearphishing Attachment |
| T1566.002 | Phishing: Spearphishing Link |
| T1036 | Masquerading |
| T1027 | Obfuscated Files or Information |
| T1583.001 | Acquire Infrastructure: Domains |
| T1583.006 | Acquire Infrastructure: Web Services |
| T1585.001 | Establish Accounts |
| T1204 | User Execution |
Tactics, Techniques & Procedures (TTPs)
Initial Access
Phishing Emails
Threat actors distribute large volumes of phishing emails masquerading as business funding opportunities.
Legitimate Marketing Platforms
Abuse of trusted email marketing infrastructure increases sender reputation and delivery success.
Defense Evasion
Unicode Obfuscation
Insertion of invisible Unicode characters within:
- subject lines
- email body text
- sender names
- hyperlinks
ASCII Smuggling
Hidden Unicode characters break detection signatures while remaining invisible to victims.
AI-Era Evasion Reuse
The technique originated from prompt-injection research and was adapted for conventional phishing campaigns.
Credential Collection
Observed campaigns attempted to collect:
- Business information
- Financial records
- Loan application data
- User credentials
- Contact information
Indicators of Compromise (IOCs)
High-Risk Unicode Ranges
Monitor for:
U+E0000 – U+E007F
Unicode Tag Characters
Additional Suspicious Invisible Characters
U+200B Zero Width Space
U+200C Zero Width Non-Joiner
U+200D Zero Width Joiner
U+2060 Word Joiner
U+FEFF Zero Width No-Break Space
U+3164 Hangul Filler
U+2800 Braille Pattern Blank
Email Characteristics
Subjects Containing Financial Lures
Examples:
- Business Funding Available
- SBA Loan Approval
- Working Capital Offer
- Merchant Cash Advance
- Business Credit Application
When combined with invisible Unicode characters, treat these as high-risk.
Infrastructure Indicators
Microsoft identified:
- Approximately 148 finance-related domains
- Extensive use of ActiveCampaign delivery infrastructure
- High-volume weekday transmission patterns
Defenders should baseline email flows to identify similar sender behavior.
Detection Opportunities
Microsoft 365 Defender
Hunt for Unicode Tags:
KQL Example
1 EmailEvents
2 | where Subject matches regex @”[\U000E0000-\U000E007F]”
Exchange Online Transport Rules
Flag messages containing:
- Unicode Tags block characters
- Zero-width characters
- Excessive hidden Unicode content
Secure Email Gateway Controls
Normalize text prior to:
- keyword inspection
- regex inspection
- machine learning classification
Microsoft specifically recommends stripping or normalizing Unicode tag characters before inspection, rather than evaluating the raw text.
Recommendations
Immediate Actions
High Priority
- Review email gateway Unicode handling
- Enable Unicode normalization before content inspection
- Implement detection for:
- U+E0000-U+E007F
- Zero-width characters
- Hidden Unicode strings
- Update phishing detection rules to operate on normalized content
- Alert on anomalous Unicode usage in:
- Subject lines
- Sender display names
- URLs
- Message bodies
Microsoft 365 Recommendations
Defender for Office 365
- Enable Safe Links
- Enable Safe Attachments
- Enable Anti-Phishing Policies
- Enable Mailbox Intelligence
- Review Threat Explorer for finance-themed campaigns
Although the campaign successfully evaded some content-based detections, Microsoft reported that Defender for Office 365 still detected over 99% of the identified messages using sender reputation, domain reputation, behavioral analytics, and infrastructure-based detections.
User Awareness Guidance
Train users to:
- Verify financial offers independently
- Scrutinize unexpected loan or funding opportunities
- Report suspicious emails
- Avoid clicking links from unsolicited financial communications
- Validate sender organizations through alternate channels
Executive Takeaway
While advanced phishing detection technologies are critical, organizations should recognize that email filtering alone is not a complete cybersecurity strategy. Threat actors continuously adapt their tactics, whether through Unicode obfuscation, AI-generated content, domain spoofing, living-off-the-land techniques, or other evasion methods specifically designed to bypass preventative controls. Assume some malicious messages will inevitably reach users despite the best available defenses.
For this reason, organizations should adopt a defense-in-depth approach that combines prevention, detection, investigation, response, and recovery capabilities. Effective programs include not only email security controls, but also documented incident response playbooks, automated containment actions, threat hunting processes, endpoint detection and response (EDR), identity monitoring, and security operations center (SOC) functions capable of identifying and mitigating threats that evade initial detection. When suspicious messages or indicators are identified, organizations should be prepared to rapidly quarantine emails, revoke malicious links, isolate compromised endpoints, initiate credential resets, conduct enterprise-wide threat hunts, and assess the scope of potential compromise.
Modern security operations increasingly leverage AI-assisted triage and sandboxing technologies to analyze suspicious emails, URLs, attachments, and behavioral indicators at machine speed. These capabilities help security teams prioritize threats, reduce analyst workload, accelerate investigations, and improve overall detection accuracy. Combined with proactive threat hunting and automated response workflows, AI-assisted analysis can significantly reduce both attacker dwell time and organizational risk.
Blackswan Cybersecurity helps organizations build and manage these comprehensive cybersecurity programs through strategic advisory services, managed security operations, and security technology integration. Blackswan’s services include cybersecurity assessments and vCISO advisory, fully managed MSSP/SOC and XDR services, proactive threat hunting, incident response readiness, tabletop exercises, and deployment of industry-leading technologies such as Huntress Managed EDR, IronScales Email Security and Phishing Protection, Microsoft security solutions, and other advanced detection and response platforms. Together, these capabilities help organizations move beyond simple prevention and establish a mature security program focused on rapid detection, containment, and resilience against today’s evolving threat landscape.
Need Assistance or Want to Discuss Further?
Contact Blackswan Cybersecurity at 855-BLK-SWAN or Contact@BlackswanCybersecurity.com