Hackers Abuse AI-Era ASCII Smuggling to Hide Phishing Content in Millions of Emails
ID: 8bcda6e4-6950-5b5e-acaa-5c8e7177a006
STIX ID: report--8bcda6e4-6950-5b5e-acaa-5c8e7177a006
Feed Name: GBHackers
Microsoft observed a mass phishing campaign that repurposed an AI-era prompt-injection technique — inserting invisible Unicode Tag block characters (U+E0000–U+E007F, notably U+E0020) into finance-related keywords — to evade keyword- and NLP-based email defenses; the operation, largely delivered via ActiveCampaign infrastructure, spiked to over 2.3 million messages/day, ran with a weekday-only cadence for about three months, and was largely mitigated by layered Defender protections, while defenders are advised to normalize invisible characters before matching and to monitor for the tag-range characters.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
