Skip to content
Tech News
← Back to articles

Attackers conceal phishing lures using invisible Unicode characters

read original get Yubico YubiKey 5C NFC Security Key → more articles
Why This Matters

A high-volume phishing campaign is abusing invisible Unicode Tags characters to split finance-related keywords, defeating keyword-based email filters. It shows that classic word-list detection is brittle, and that layered signals like sender reputation are what actually catch these messages. The same ASCII smuggling trick already appears in AI prompt injection, hinting at wider abuse.

Key Takeaways
Worth a Look

Yubico YubiKey 5C NFC Security Key — When phishing emails slip past filters using invisible Unicode tricks, a hardware key is the backstop that stops stolen passwords from becoming stolen accounts. The YubiKey 5C NFC plugs into USB-C or taps NFC phones for phishing-resistant sign-ins across Microsoft, Google, and many other accounts. It's a tiny, batteryless thing to keep on your keychain and forget about until it saves you.

See Yubico YubiKey 5C NFC Security Key on Amazon → Affiliate link — we may earn a commission on purchases, at no extra cost to you. Product picked by AI based on this article; it is not a tested recommendation.

Threat actors have adopted the ASCII smuggling technique in phishing campaigns, using invisible Unicode characters to evade email security filters.

ASCII smuggling has been used in AI prompt injection attacks to conceal malicious instructions from users by encoding them with Unicode characters from the Tags block (U+E0000–U+E007F).

Microsoft threat researchers discovered a large-scale phishing campaign using this technique, which peaked at up to 2.37 million daily messages in late February. Although the volume has dropped gradually in May, the operation is still active.

“The high-volume phase persisted for roughly three months after February 9 and dropped sharply after May 15, 2026,” explains Microsoft.

“These dates bound the observed use of the specific technique in our telemetry, not the broader campaign, which started earlier without it and continued without it.”

Phishing email delivery volumes

Source: Microsoft

In this campaign, the attacker inserts an invisible Unicode character inside finance-related lure words to split them.

In doing so, a keyword like ‘funding’ becomes something like ‘fun[invisible character]ding’ and evades email filters that rely on word lists to detect suspicious or malicious messages.

Sample of a phishing message

... continue reading