A new phishing campaign has emerged that leverages ASCII smuggling, a technique usually employed to hide malicious prompts for AI models. Microsoft has identified this method being used in a significant email phishing operation that peaked at over 2.37 million messages in late February 2026.
Details of the Campaign
The campaign, which began to gain traction in early February, showed a marked increase in activity, with Microsoft flagging around 21,000 suspicious messages on February 8. This number surged to more than 1.3 million the following day. The phishing emails primarily originated from approximately 150 finance-themed domains and continued at a high volume until mid-June, with a notable decline after May 15.
How ASCII Smuggling Works
ASCII smuggling involves the use of invisible Unicode characters to conceal content within text that appears normal to human readers. In this case, attackers inserted Unicode tag spaces between letters in financial terms to bypass keyword matching and content filters. For example, the word “funding” was altered to “fun⟨U+E0020⟩ding,” effectively splitting the word to evade detection.
Implications for Security
Microsoft’s researchers, Noam Kochavi and Sarah Wolstencroft, emphasized the importance of recognizing how techniques from AI security can transition into traditional phishing methods. They noted that as understanding of AI-related attack methods evolves, threat actors may adapt these techniques for more conventional threats.
Recommendations for Defenders
To mitigate risks associated with this type of phishing attack, Microsoft advises that organizations ensure their normalization and tokenization processes effectively handle tag characters. This includes stripping or folding invisible Unicode code points from any content evaluated by keyword or signature matching. Additionally, monitoring for behavioral indicators, such as spikes in emails from finance-themed disposable domains, can help identify potential phishing campaigns.
Overall, the adaptation of ASCII smuggling in phishing attacks highlights the need for continuous vigilance and adaptation in cybersecurity practices.
This article was produced by NeonPulse.today using human and AI-assisted editorial processes, based on publicly available information. Content may be edited for clarity and style.








