logo

Hackers Abuse AI-Era ASCII Smuggling to Hide Phishing Content in Millions of Emails

ID: 8bcda6e4-6950-5b5e-acaa-5c8e7177a006

STIX ID: report--8bcda6e4-6950-5b5e-acaa-5c8e7177a006

Feed Name: GBHackers

Threat Score
55/100

Date Published: 2026-09-04

Date Updated: 2026-09-11

Author: Mayura Kathir

...
...

Microsoft observed a mass phishing campaign that repurposed an AI-era prompt-injection technique — inserting invisible Unicode Tag block characters (U+E0000–U+E007F, notably U+E0020) into finance-related keywords — to evade keyword- and NLP-based email defenses; the operation, largely delivered via ActiveCampaign infrastructure, spiked to over 2.3 million messages/day, ran with a weekday-only cadence for about three months, and was largely mitigated by layered Defender protections, while defenders are advised to normalize invisible characters before matching and to monitor for the tag-range characters.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.