Phishing Campaign Sends Millions of Emails Using Invisible Unicode to Evade Filters
AI-summarised brief · reviewed before publication
Microsoft warned of a high‑volume phishing campaign nationwide that uses invisible Unicode tag characters to split financial lure words and evade email filters. The technique, known as ASCII smuggling, inserts non‑rendering code points from the deprecated Unicode Tags block (U+E0000‑U+E007F) into keywords such as “funding,” rendering them readable to users while breaking literal string matches used by security tools. The operation began in early February 2026, peaked on February 26 with 1‑2.37 million messages per day, and followed a weekly cadence that paused on weekends. Over three months it sent multi‑million daily emails before dropping sharply significantly after May 15. The campaign is linked to a broader effort that weaponized the ActiveCampaign platform to deliver AI‑generated, finance‑themed phishing targeting SBA loan applicants.
💡 Why It Matters
- · By exploiting Unicode tags, attackers bypass conventional filters at scale, forcing security teams to redesign detection logic for invisible characters.