Microsoft Warns Of Unicode Based Phishing Campaign Bypassing Email Security Filters

Microsoft Warns Of Unicode Based Phishing Campaign Bypassing Email Security Filters

Microsoft has warned of a high volume phishing campaign that is using invisible Unicode tag characters to bypass email security filters, demonstrating how techniques originally associated with AI prompt injection are now being adapted for large scale phishing operations. According to Microsoft Security Research, attackers are inserting invisible Unicode characters into common financial keywords such as “funding” to prevent email filters from recognizing them while keeping the text unchanged for recipients. Instead of using these hidden characters to conceal instructions for artificial intelligence models, the attackers have repurposed the technique to split words in phishing emails, allowing malicious messages to evade traditional keyword based detection systems. Microsoft noted that attacks using this approach first appeared in early February 2026, highlighting an evolution in phishing tactics that combines AI era evasion methods with conventional email based threats.

The campaign relies on a technique known as ASCII Smuggling, where invisible or non rendering Unicode characters are embedded inside otherwise harmless looking text. Human users cannot see these characters, making emails appear completely normal, but security tools and automated processing systems may interpret the hidden content differently. Microsoft explained that the Unicode Tags block, ranging from U+E0000 to U+E007F, has been the most frequently abused portion of the Unicode standard. Originally intended for language tagging and now largely deprecated, this character range contains invisible equivalents of printable ASCII characters. As a result, a financial keyword such as “funding” can be transformed by inserting an invisible Unicode tag in the middle of the word, allowing it to bypass detection systems searching for exact keyword matches while still appearing unchanged to recipients. Microsoft stated that the phishing campaign remained highly active for approximately three months before activity declined sharply after May 15, 2026. During its peak, weekday email volumes ranged from one million to 2.37 million messages, with the highest activity recorded on February 26, 2026. The campaign followed a consistent weekly pattern, operating heavily during weekdays while becoming significantly quieter over weekends.

Microsoft has linked the activity to a broader phishing operation that previously abused the ActiveCampaign marketing automation platform to distribute thousands of AI generated phishing emails targeting Small Business Administration loan applicants. The campaign was first documented by Fortra Intelligence and Research Experts in September 2025, which reported that attackers focused on gathering detailed business and financial information to support more targeted phishing attacks in the future. Fortra also observed that threat actors were using ActiveCampaign artificial intelligence capabilities to automatically generate convincing phishing websites with varying layouts, content, and workflows, enabling large scale phishing campaigns to be produced more efficiently. In the latest campaign, Microsoft identified hundreds of disposable finance themed sender domains impersonating business loan, line of credit, and advance funding providers. Email messages sent from these domains were routed through ActiveCampaign infrastructure, causing outbound links to pass through the platform’s click tracking domains, including acemlnd.com and activehosted.com. This routing allowed malicious messages to originate from a reputable email marketing platform, making them appear more legitimate to reputation based filtering systems.

Microsoft emphasized that while the use of invisible or visually similar characters has been observed previously in phishing and homoglyph attacks, the scale of this campaign and its specific use of the Unicode Tags block represent a notable shift in phishing techniques. The company said that heavy use of invisible Unicode characters can serve as an indicator of suspicious activity, while ActiveCampaign confirmed that its content moderation systems evaluate emails containing invisible Unicode characters in the same way as unobfuscated messages and also treat excessive use of the technique as a suspicious signal. Microsoft further noted that abuse of trusted marketing platforms can complicate email reputation based filtering because malicious traffic may closely resemble legitimate marketing communications. The findings demonstrate how cybercriminals continue adapting emerging technologies and lesser known technical features to improve the effectiveness of phishing campaigns while attempting to reduce the likelihood of detection by traditional email security controls.

Source

Follow the SPIN IDG WhatsApp Channel for updates across the Smart Pakistan Insights Network covering all of Pakistan’s technology ecosystem. 

Post Comment