Phishing Campaign Exploits ASCII Smuggling Techniques

Phishing Campaign Exploits ASCII Smuggling Techniques

First seen 4 Sep 2026, 14:46 UTC Blogs.Microsoftembracethered.comGbhackersatlas.mitre.orgwww.fortra.com 67.5

Article Content

Browse articles
ThreatCluster

Microsoft researchers identified a large-scale phishing campaign utilizing ASCII smuggling, which employs invisible Unicode characters to evade email security filters. This technique, initially popularized in AI prompt injection, has been adapted by cybercriminals to hide financial lure keywords in phishing emails. The campaign reportedly sent over 2.3 million messages per day, indicating a significant threat to organizations relying on traditional email security measures. Microsoft Defender for Office 365 telemetry showed a sharp increase in detections of this method starting February 9, 2026. The attack leverages the Unicode Tags block (U+E0000 to U+E007F), allowing attackers to obscure malicious content from human readers while remaining detectable by AI systems. As of now, the threat remains active, with ongoing detections and adaptations in phishing strategies.

Key Points: • Over 2.3 million phishing emails per day using ASCII smuggling techniques. • Attackers hide financial lure keywords using invisible Unicode characters. • Microsoft Defender telemetry shows increased detection rates since February 2026.

Ask AI about this cluster

Timeline

2026-02-09
Increase in ASCII smuggling detections
Microsoft telemetry recorded a sharp rise in detections of ASCII smuggling techniques in phishing emails.
Blogs.Microsoft
2026-09-03
Microsoft reports on phishing campaign
Microsoft published findings on a phishing campaign using ASCII smuggling, reaching over 2.3 million messages daily.
Blogs.Microsoft
2026-09-04
Gbhackers reports on ASCII smuggling
Gbhackers highlighted the abuse of ASCII smuggling in phishing attacks, confirming the scale of the threat.
Gbhackers