Phishing Campaign Sends Millions of Emails Using Invisible Unicode to Evade Filters
https://firewall.firm.in/wp-content/uploads/2026/09/emails.jpg

Microsoft is alerting of a “high-volume phishing campaign” that’s using invisible Unicode tag characters to bypass email filters.
“Instead of using these characters to hide instructions from people while exposing them to AI models, the attacker used them to split financial lure words such as ‘funding’ to prevent email filters from parsing them,” the Microsoft Security Research team said.
The Windows maker said the findings show AI-era evasion techniques can be adapted by threat actors in traditional phishing and spam campaigns. Attacks exploiting this approach are said to have first emerged in early February 2026.
ASCII Smuggling refers to a technique where invisible or non-rendering Unicode characters are used to conceal messages or instructions inside seemingly-harmless text. As a result, human user interfaces do not render them, making the text appear completely normal to the user.
However, such content can be ingested by email filters or AI language models, mistakenly treating it as real text. This, in turn, can open the door to prompt injection by taking advantage of the fact that large language models (LLMs) cannot draw a reliable boundary between genuine user instructions entered directly into a prompt and content embedded into benign-looking text or other third-party sources such as web pages, documents, or emails.
“The most abused range is the Unicode Tags block, U+E0000 to U+E007F,” Microsoft said. “This block contains a shadow copy of the printable ASCII characters (for example, U+E0041 mirrors ‘A,’ U+E0061 mirrors ‘a’). The block was originally intended for language tagging and is now largely deprecated.”
According to the Windows maker, the ASCII smuggling-oriented phishing campaign entered into a high-volume phase for roughly three months before dropping sharply post May 15, 2026. The activity is said to have followed a weekly cadence, with the campaign almost going radio silent on weekends and resuming in full swing on Mondays.
Weekday volumes are estimated to reach anywhere between 1 to 2.37 million messages, hitting a peak on February 26, 2026. The campaign is assessed to be tied to a broader phishing campaign that weaponized the ActiveCampaign marketing and automation platform to distribute thousands of AI-generated phishing emails targeting Small Business Administration (SBA) loan applicants.
Details of the phishing campaign were disclosed by the Fortra Intelligence and Research Experts (FIRE) team in September 2025, stating the operation focuses on collecting detailed business and financial information, likely to enable highly targeted spear‑phishing in future attacks.
“The campaign’s sophistication and uniqueness lies in the ability to mass‑produce convincing, tailored websites that adapt to different illegitimate or impersonated domains,” Fortra noted at the time. “Threat actors are able to scale sophisticated phishing by using ActiveCampaign’s AI-powered marketing automation features to vary the design, content, and flow, ultimately creating more convincing phishing campaigns, quicker.”
The latest set of phishing emails, per Microsoft, leverages the invisible tag characters as an obfuscation pattern, inserting them inside common financial keywords so as to split them apart and get around email filters looking for keyword or literal signature matches.
For instance, a finance-related lure term such as “funding” becomes “fun⟨U+E0020⟩ding,” so that it looks normal to the email recipient while having the side effect of bypassing email security controls.
“To a recipient, and to parsing pipelines that drop or normalize these characters, the word still reads as funding,” Microsoft explained. “To a detector matching the literal string funding, or a regex that does not account for interleaved invisible code points, the byte sequence no longer contains the contiguous keyword.”
While the use of invisible or look-alike characters is not a new technique in phishing and homoglyph attacks, what’s novel is the choice of the characters used – namely, the Unicode Tags block – and the scale of the campaign itself, which has generated multi-million messages on a daily basis.
The campaign has been found to leverage hundreds of disposable, finance-themed sender domains using lures that mimicked business loan, line-of-credit, and advance-funding phishing patterns that are typically associated with fraud or credential-harvesting schemes. The top 10 sender domains by the most hits are listed below –
- guardiangrowthfunding[.]com
- digitalcapitalboost[.]com
- thebusinessloanexpress[.]com
- yourlocfunding[.]com
- advancefundingboost[.]com
- guardiancapitalway[.]com
- harboradvancefunding[.]com
- unitedfundingwave[.]com
- directcapitalboost[.]com
- onlinedirectfinance[.]com
What’s more, these emails from these finance-themed domains are relayed through ActiveCampaign, causing every outbound link in the message body to be routed via its own click-tracking domains (“acemlnd[.]com” and “activehosted[.]com”).
ActiveCampaign, for its part, said it has tested its content-moderation systems with messages containing invisible Unicode characters, and that such emails receive the moderation verdict as their unobfuscated equivalents. It also said a heavy use of the technique is treated as a “suspicious signal.”
“As with any shared sending service, attacker abuse of customer accounts or workflows can complicate reputation-based filtering,” Microsoft said. “By originating from a reputable marketing platform with established IP reputation and authentication, the activity may appear more similar to legitimate marketing traffic and can complicate reputation-based filtering.”
Firewall Security Company India Complete Firewall Security Solutions Provider Company in India











