ASCII Smuggling: Invisible Unicode Tag Characters Split 'Funding' Lures Past Content Filters (Microsoft, 2026-09-05 CISO Daily Digest)
Microsoft detailed a high-volume phishing campaign that abuses invisible Unicode tag characters — the deprecated Tags block U+E0000 to U+E007F, which shadows printable ASCII — to split financial lure words such as "funding" so email content filters cannot parse the payload while the message renders normally to humans. The campaign ran roughly February to mid-May 2026 at weekday volumes of 1–2.37 million messages a day (peak February 26), followed a weekly cadence and went nearly silent on weekends; Microsoft links it to the broader AI-generated phishing wave that weaponized the ActiveCampaign marketing platform against Small Business Administration loan applicants (first documented by Fortra FIRE in September 2025) — an example of AI-era evasion techniques being recycled into classical spam. This demo reproduces the construct as a document-borne lure: a DOCX in which each letter of the word "funding" is paired with its invisible U+E0000-block shadow character, so the contiguous keyword never appears in the raw text a lexical filter inspects, while the message still reads as a normal funding-application lure (marked DEMO, executes nothing). A sanitized copy has the shadow characters removed. OPSWAT AI Content Inspector inspects what lexical filters miss: it reads the document content and flags the phishing intent before the lure reaches the inbox or the model (MITRE ATT&CK T1566.001 spearphishing attachment).
Attack Technique
Phishing lure obfuscation with deprecated Unicode tag characters (U+E0000–U+E007F, shadowing printable ASCII) to split financial keywords such as 'funding' past lexical content filters (Microsoft-documented 'ASCII smuggling' wave, Feb–mid-May 2026; ActiveCampaign/SBA-loan lure lineage per Fortra FIRE; T1566.001)
MITRE ATT&CK
T1566.001 ↗Platforms
File Types
MetaDefender Capabilities
Incident Coverage
This attack technique maps to a real-world security incident — read the daily digest for details: Read the incident digest ↗