THREAT ADVISORY ASCII Smuggling (Unicode Phishing) September 8, 2026

DOWNLOAD PDF

THREAT ADVISORY

Executive Summary

Microsoft researchers recently disclosed a large-scale phishing campaign leveraging invisible Unicode characters to bypass traditional email security controls. The technique, referred to as ASCII Smuggling or Unicode Obfuscation, inserts non-rendering Unicode characters into phishing lure words such as “funding,” “credit,” “capital,” and “loan.” To users, the text appears completely normal. However, email filters, keyword-based detections, regular expressions, and some machine learning pipelines may fail to recognize the modified words.

Microsoft observed the campaign reaching up to 2.37 million phishing emails per day during its peak in February 2026. The operation used about 148 finance-themed domains and legitimate marketing infrastructure, including ActiveCampaign, to distribute malicious content.

This campaign demonstrates how threat actors are adapting techniques originally developed for AI prompt injection attacks and repurposing them for traditional phishing operations. Organizations relying heavily on keyword detection, content signatures, or pattern matching are particularly susceptible to this evasion method.

Threat Overview

Attribute Details
Threat Type Phishing / Email Evasion
Technique Unicode Obfuscation / ASCII Smuggling
Primary Objective Deliver phishing content while evading email filters
Initial Access Email
Affected Platforms Microsoft 365, Google Workspace, Secure Email Gateways
Targeting Business finance organizations, SMBs, loan applicants
Scale Observed Up to 2.37 million emails/day
Infrastructure Finance-themed domains, marketing automation services
Impact Credential theft, financial fraud, business email compromise (BEC)

Technical Analysis

How the Attack Works

Most email filtering technologies inspect message content for suspicious strings including:

  • funding
  • loan
  • credit
  • advance
  • capital
  • payment
  • invoice
  • wire transfer

Attackers insert invisible Unicode characters between letters:

 Normal Word

funding

 Unicode Obfuscated

fun<U+E0064>tag-character<…>ding

To the recipient, both appear identical. To many filtering engines:

fun ding

or

fun[hidden_unicode]ding

which bypasses exact-match keyword inspections.

Unicode Tags Block Abuse

The primary Unicode range abused is:

U+E0000 – U+E007F

Known as the Unicode Tags Block.

Characteristics:

  • Non-printable
  • Not rendered in common user interfaces
  • Originally intended for language tagging
  • Largely deprecated
  • Can encode ASCII-equivalent characters invisibly

Microsoft identified this as the most commonly abused Unicode range within the campaign.

Example

A phishing email promoting fraudulent SBA funding opportunities may contain:

Visible text:

Small Business Funding Available

Underlying encoded text:

Small Business Fun<tag>ding Available

A user sees:

Small Business Funding Available

A filter looking for the keyword “funding” may fail to match the pattern.

Campaign Observations

Microsoft telemetry identified:

  • Peak activity on February 26, 2026
  • Approximately 148 finance-themed sender domains
  • Activity concentrated during weekdays
  • Significant reduction on weekends
  • Roughly three-month period of large-scale activity
  • Continued lower-volume activity after May 2026

The phishing lures predominantly focused on:

  • Business funding
  • SBA loans
  • Credit services
  • Capital advances
  • Financial assistance programs

MITRE ATT&CK Mapping

ATT&CK ID Technique
T1566.001 Phishing: Spearphishing Attachment
T1566.002 Phishing: Spearphishing Link
T1036 Masquerading
T1027 Obfuscated Files or Information
T1583.001 Acquire Infrastructure: Domains
T1583.006 Acquire Infrastructure: Web Services
T1585.001 Establish Accounts
T1204 User Execution

Tactics, Techniques & Procedures (TTPs)

Initial Access

Phishing Emails

Threat actors distribute large volumes of phishing emails masquerading as business funding opportunities.

 Legitimate Marketing Platforms

Abuse of trusted email marketing infrastructure increases sender reputation and delivery success.

Defense Evasion

Unicode Obfuscation

Insertion of invisible Unicode characters within:

  • subject lines
  • email body text
  • sender names
  • hyperlinks

ASCII Smuggling

Hidden Unicode characters break detection signatures while remaining invisible to victims.

AI-Era Evasion Reuse

The technique originated from prompt-injection research and was adapted for conventional phishing campaigns.

Credential Collection

Observed campaigns attempted to collect:

  • Business information
  • Financial records
  • Loan application data
  • User credentials
  • Contact information

 Indicators of Compromise (IOCs)

High-Risk Unicode Ranges

Monitor for:

U+E0000 – U+E007F

Unicode Tag Characters

Additional Suspicious Invisible Characters

U+200B  Zero Width Space

U+200C  Zero Width Non-Joiner

U+200D  Zero Width Joiner

U+2060  Word Joiner

U+FEFF  Zero Width No-Break Space

U+3164  Hangul Filler

U+2800  Braille Pattern Blank

Email Characteristics

Subjects Containing Financial Lures

Examples:

  • Business Funding Available
  • SBA Loan Approval
  • Working Capital Offer
  • Merchant Cash Advance
  • Business Credit Application

When combined with invisible Unicode characters, treat these as high-risk.

 Infrastructure Indicators

Microsoft identified:

  • Approximately 148 finance-related domains
  • Extensive use of ActiveCampaign delivery infrastructure
  • High-volume weekday transmission patterns

Defenders should baseline email flows to identify similar sender behavior.

Detection Opportunities

Microsoft 365 Defender

Hunt for Unicode Tags:

KQL Example

1 EmailEvents

2 | where Subject matches regex @”[\U000E0000-\U000E007F]”

Exchange Online Transport Rules

Flag messages containing:

  • Unicode Tags block characters
  • Zero-width characters
  • Excessive hidden Unicode content

Secure Email Gateway Controls

Normalize text prior to:

  • keyword inspection
  • regex inspection
  • machine learning classification

Microsoft specifically recommends stripping or normalizing Unicode tag characters before inspection, rather than evaluating the raw text.

Recommendations

Immediate Actions

High Priority

  1. Review email gateway Unicode handling
  2. Enable Unicode normalization before content inspection
  3. Implement detection for:
    1. U+E0000-U+E007F
    2. Zero-width characters
    3. Hidden Unicode strings
  4. Update phishing detection rules to operate on normalized content
  5. Alert on anomalous Unicode usage in:
    1. Subject lines
    2. Sender display names
    3. URLs
    4. Message bodies

Microsoft 365 Recommendations

Defender for Office 365

  • Enable Safe Links
  • Enable Safe Attachments
  • Enable Anti-Phishing Policies
  • Enable Mailbox Intelligence
  • Review Threat Explorer for finance-themed campaigns

Although the campaign successfully evaded some content-based detections, Microsoft reported that Defender for Office 365 still detected over 99% of the identified messages using sender reputation, domain reputation, behavioral analytics, and infrastructure-based detections.

User Awareness Guidance

Train users to:

  • Verify financial offers independently
  • Scrutinize unexpected loan or funding opportunities
  • Report suspicious emails
  • Avoid clicking links from unsolicited financial communications
  • Validate sender organizations through alternate channels

 Executive Takeaway

While advanced phishing detection technologies are critical, organizations should recognize that email filtering alone is not a complete cybersecurity strategy. Threat actors continuously adapt their tactics, whether through Unicode obfuscation, AI-generated content, domain spoofing, living-off-the-land techniques, or other evasion methods specifically designed to bypass preventative controls. Assume some malicious messages will inevitably reach users despite the best available defenses.

For this reason, organizations should adopt a defense-in-depth approach that combines prevention, detection, investigation, response, and recovery capabilities. Effective programs include not only email security controls, but also documented incident response playbooks, automated containment actions, threat hunting processes, endpoint detection and response (EDR), identity monitoring, and security operations center (SOC) functions capable of identifying and mitigating threats that evade initial detection. When suspicious messages or indicators are identified, organizations should be prepared to rapidly quarantine emails, revoke malicious links, isolate compromised endpoints, initiate credential resets, conduct enterprise-wide threat hunts, and assess the scope of potential compromise.

Modern security operations increasingly leverage AI-assisted triage and sandboxing technologies to analyze suspicious emails, URLs, attachments, and behavioral indicators at machine speed. These capabilities help security teams prioritize threats, reduce analyst workload, accelerate investigations, and improve overall detection accuracy. Combined with proactive threat hunting and automated response workflows, AI-assisted analysis can significantly reduce both attacker dwell time and organizational risk.

Blackswan Cybersecurity helps organizations build and manage these comprehensive cybersecurity programs through strategic advisory services, managed security operations, and security technology integration. Blackswan’s services include cybersecurity assessments and vCISO advisory, fully managed MSSP/SOC and XDR services, proactive threat hunting, incident response readiness, tabletop exercises, and deployment of industry-leading technologies such as Huntress Managed EDR, IronScales Email Security and Phishing Protection, Microsoft security solutions, and other advanced detection and response platforms. Together, these capabilities help organizations move beyond simple prevention and establish a mature security program focused on rapid detection, containment, and resilience against today’s evolving threat landscape.

Need Assistance or Want to Discuss Further?

Contact Blackswan Cybersecurity at 855-BLK-SWAN or Contact@BlackswanCybersecurity.com

CONTACT US