HackMyIP
← Back to News
2026-09-04 The Hacker News

Massive Phishing Campaign Uses Invisible Unicode to Slip Past Email Filters

PhishingAI ThreatsThreat Intel

Microsoft's Security Research team has issued a warning about a high-volume phishing campaign that leverages invisible Unicode tag characters to evade email security filters. The technique, known as ASCII Smuggling, hides malicious instructions inside seemingly normal text by exploiting the Unicode Tags block (U+E0000 to U+E007F), a shadow copy of printable ASCII characters that human interfaces do not render. Attackers used these characters to split financial lure words such as "funding," preventing parsing by filter systems while keeping the message appearing completely normal to recipients.

The campaign entered a high-volume phase for roughly three months before dropping sharply after May 15, 2026. Activity followed a strict weekly cadence — nearly silent on weekends, resuming at full capacity on Mondays — with daily volumes ranging from 1 to 2.37 million messages and peaking on February 26, 2026. Microsoft noted that this case demonstrates how AI-era evasion techniques are being repurposed in conventional phishing and spam operations, since large language models can ingest these invisible characters and treat them as legitimate instructions, opening the door to prompt injection attacks.

Researchers have linked the activity to a broader phishing operation that weaponized the ActiveCampaign marketing and automation platform to distribute AI-generated emails impersonating U.S. Small Business Administration (SBA) loan programs. The Fortra Intelligence and Research Experts (FIRE) team first disclosed this connected campaign in September 2025, noting that it harvests detailed business and financial information to enable highly targeted follow-on spear-phishing. "Threat actors are able to scale sophisticated phishing by using ActiveCampaign's AI-powered tools to mass-produce convincing, tailored websites that adapt to different impersonated domains," Fortra stated at the time.

With invisible-character phishing now operating at million-message scale, both individuals and organizations need to harden their detection and identity exposure posture. Use a email breach checker to confirm whether addresses in your domain have appeared in known compromises, run a DNS leak test to verify your resolver isn't leaking queries to untrusted networks, and complete a privacy checkup to ensure your browser and email client are not leaking metadata that could be correlated with attacker reconnaissance.

Source: The Hacker News →

Related Tools

Check whether this kind of story affects you — free, no signup:

Email Auth Check →Email Breach Check →Privacy Checkup →

Related Guides

Learn the background behind this story:

How phishing attacks work →How to check if an email is safe →SPF, DKIM & DMARC explained →