ASCII smuggling moves from prompt injection research into phishing-filter evasion

Published 09 Sep 2026 · Severity: medium

Microsoft Security Research has documented a phishing campaign that inserted invisible Unicode tag characters into finance-themed words so messages remained readable to recipients while content filters saw broken strings. Microsoft observed a sharp increase in its hunting signal from 9 February 2026 and said the activity remained elevated on weekdays for roughly three months. The technique is also relevant to AI assistants that ingest raw email because the hidden characters remain present in the underlying text. Microsoft recommends normalising invisible Unicode before content matching and before AI ingestion.