Microsoft is alerting of a “high-volume phishing marketing campaign” that is utilizing invisible Unicode tag characters to bypass e mail filters.
“As an alternative of utilizing these characters to cover directions from folks whereas exposing them to AI fashions, the attacker used them to separate monetary lure phrases similar to ‘funding’ to forestall e mail filters from parsing them,” the Microsoft Safety Analysis crew mentioned.
The Home windows maker mentioned the findings present AI-era evasion strategies will be tailored by risk actors in conventional phishing and spam campaigns. Assaults exploiting this strategy are mentioned to have first emerged in early February 2026.
ASCII Smuggling refers to a way the place invisible or non-rendering Unicode characters are used to hide messages or directions inside seemingly-harmless textual content. In consequence, human person interfaces don’t render them, making the textual content seem utterly regular to the person.
Nevertheless, such content material will be ingested by e mail filters or AI language fashions, mistakenly treating it as actual textual content. This, in flip, can open the door to immediate injection by benefiting from the truth that giant language fashions (LLMs) can’t draw a dependable boundary between real person directions entered immediately right into a immediate and content material embedded into benign-looking textual content or different third-party sources similar to internet pages, paperwork, or emails.
“Probably the most abused vary is the Unicode Tags block, U+E0000 to U+E007F,” Microsoft mentioned. “This block comprises a shadow copy of the printable ASCII characters (for instance, U+E0041 mirrors ‘A,’ U+E0061 mirrors ‘a’). The block was initially supposed for language tagging and is now largely deprecated.”
In keeping with the Home windows maker, the ASCII smuggling-oriented phishing marketing campaign entered right into a high-volume part for roughly three months earlier than dropping sharply put up Could 15, 2026. The exercise is alleged to have adopted a weekly cadence, with the marketing campaign virtually going radio silent on weekends and resuming in full swing on Mondays.
Weekday volumes are estimated to achieve wherever between 1 to 2.37 million messages, hitting a peak on February 26, 2026. The marketing campaign is assessed to be tied to a broader phishing marketing campaign that weaponized the ActiveCampaign advertising and automation platform to distribute 1000’s of AI-generated phishing emails focusing on Small Enterprise Administration (SBA) mortgage candidates.
Particulars of the phishing marketing campaign have been disclosed by the Fortra Intelligence and Analysis Consultants (FIRE) crew in September 2025, stating the operation focuses on amassing detailed enterprise and monetary info, prone to allow extremely focused spear‑phishing in future assaults.
“The marketing campaign’s sophistication and uniqueness lies within the potential to mass‑produce convincing, tailor-made web sites that adapt to completely different illegitimate or impersonated domains,” Fortra famous on the time. “Menace actors are capable of scale refined phishing through the use of ActiveCampaign’s AI-powered advertising automation options to fluctuate the design, content material, and circulation, finally creating extra convincing phishing campaigns, faster.”
The newest set of phishing emails, per Microsoft, leverages the invisible tag characters as an obfuscation sample, inserting them inside frequent monetary key phrases in order to separate them aside and get round e mail filters on the lookout for key phrase or literal signature matches.
As an illustration, a finance-related lure time period similar to “funding” turns into “enjoyable⟨U+E0020⟩ding,” in order that it seems regular to the e-mail recipient whereas having the aspect impact of bypassing e mail safety controls.
“To a recipient, and to parsing pipelines that drop or normalize these characters, the phrase nonetheless reads as funding,” Microsoft defined. “To a detector matching the literal string funding, or a regex that doesn’t account for interleaved invisible code factors, the byte sequence not comprises the contiguous key phrase.”
Whereas using invisible or look-alike characters will not be a brand new approach in phishing and homoglyph assaults, what’s novel is the selection of the characters used – specifically, the Unicode Tags block – and the dimensions of the marketing campaign itself, which has generated multi-million messages each day.
The marketing campaign has been discovered to leverage a whole lot of disposable, finance-themed sender domains utilizing lures that mimicked enterprise mortgage, line-of-credit, and advance-funding phishing patterns which might be sometimes related to fraud or credential-harvesting schemes. The highest 10 sender domains by essentially the most hits are listed under –
- guardiangrowthfunding[.]com
- digitalcapitalboost[.]com
- thebusinessloanexpress[.]com
- yourlocfunding[.]com
- advancefundingboost[.]com
- guardiancapitalway[.]com
- harboradvancefunding[.]com
- unitedfundingwave[.]com
- directcapitalboost[.]com
- onlinedirectfinance[.]com
What’s extra, these emails from these finance-themed domains are relayed via ActiveCampaign, inflicting each outbound hyperlink within the message physique to be routed through its personal click-tracking domains (“acemlnd[.]com” and “activehosted[.]com”).
ActiveCampaign, for its half, mentioned it has examined its content-moderation techniques with messages containing invisible Unicode characters, and that such emails obtain the moderation verdict as their unobfuscated equivalents. It additionally mentioned a heavy use of the approach is handled as a “suspicious sign.”
“As with every shared sending service, attacker abuse of buyer accounts or workflows can complicate reputation-based filtering,” Microsoft mentioned. “By originating from a good advertising platform with established IP status and authentication, the exercise could seem extra much like reputable advertising visitors and may complicate reputation-based filtering.”










