- Microsoft has identified a high-volume phishing campaign using invisible Unicode tag characters to bypass email security filters.
- Dubbed “ASCII Smuggling,” the technique conceals financial lure words like “funding” by splitting them with non-rendering characters.
- The campaign peaked in late February 2026, sending up to 2.37 million messages daily, before dropping sharply after May 15, 2026.
- Threat actors exploited the ActiveCampaign marketing platform to distribute thousands of AI-generated phishing emails targeting SBA loan applicants.
Microsoft is alerting of a “high-volume phishing campaign” that uses invisible Unicode tag characters to bypass email filters, as the tech giant reported on September 3, 2026.
The technique, known as ASCII Smuggling, leverages non-rendering characters from the Unicode Tags block (U+E0000 to U+E007F) to split financial keywords like “funding” into “fun⟨U+E0020⟩ding”. Consequently, the word appears normal to recipients but evades email filters searching for literal string matches.
“To a detector matching the literal string funding, or a regex that does not account for interleaved invisible code points, the byte sequence no longer contains the contiguous keyword,” Microsoft explained.
The campaign entered a high-volume phase in early February 2026, with weekday volumes reaching between 1 and 2.37 million messages. Activity peaked on February 26 before dropping sharply after May 15, following a weekly cadence that nearly ceased on weekends.
Fortra’s Intelligence and Research Experts team previously disclosed in September 2025 that the operation focuses on collecting detailed business information, likely for future spear-phishing attacks. The campaign weaponized the ActiveCampaign marketing platform to distribute AI-generated phishing emails targeting Small Business Administration loan applicants, according to reports.
The emails used hundreds of finance-themed sender domains, including guardiangrowthfunding[.]com and digitalcapitalboost[.]com. Each outbound link was routed through ActiveCampaign’s click-tracking domains, complicating reputation-based filtering.
ActiveCampaign stated it has tested its content-moderation systems with invisible Unicode characters, noting that heavy use of the technique is treated as a “suspicious signal.”
✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.
