ASCII Smuggling Phishing Evasion Hits Microsoft 365
Summary
Microsoft researchers observed a high-volume phishing campaign using invisible Unicode tag characters, known as ASCII smuggling, to evade email filters in finance-themed lures. The technique, previously associated with AI prompt injection, shows how AI-era evasion methods are now crossing into traditional phishing, making layered email security and hunting more important for defenders.
Introduction
Microsoft has uncovered a notable shift in attacker behavior: a technique made popular in AI prompt injection research is now being used in mainstream phishing campaigns. For Microsoft 365 and security teams, this matters because it shows how evasions developed for AI systems can quickly become practical tools for email-based attacks.
What is new
Microsoft Security Research observed a large phishing campaign using invisible Unicode tag characters from the U+E0000 to U+E007F range. This method, called ASCII smuggling, lets attackers split or hide lure words such as “funding” so that the text appears normal to users but may be parsed differently by detection systems.
Key findings include:
- The activity was first surfaced through Microsoft Defender for Office 365 prompt injection protection research.
- Signature hits spiked sharply on February 9, 2026.
- Volume jumped from about 21,000 messages on February 8 to more than 1.3 million the next day.
- Peak volume exceeded 2.3 million messages on February 11.
- The campaign largely followed a weekday-only sending pattern for roughly three months.
- Microsoft linked the activity to a broader finance-themed phishing campaign using around 150 sender domains.
Why this matters for defenders
This finding highlights an important security trend: techniques first discussed in AI red-teaming and prompt injection are now being repurposed for classic phishing evasion. In this case, the same invisible Unicode characters that can hide instructions from humans while exposing them to AI models were used to obscure phishing keywords from email filters.
Microsoft also noted that detection did not rely on a single Unicode-specific rule alone. Instead, layered protections in Defender for Office 365 flagged most messages, which reinforces the value of defense in depth rather than depending on one signature.
Impact on IT administrators
For administrators, this means email hunting and detection logic should account for unusual Unicode usage, especially the Unicode Tags block. However, tuning is essential because legitimate content can also trigger detections, such as subdivision flag emojis for England, Scotland, and Wales.
Security teams should expect more crossover between AI-related attack research and traditional threat activity. Techniques that once seemed niche may quickly appear in large-scale commodity phishing.
Next steps
- Review Defender for Office 365 detections and hunting queries for suspicious Unicode tag usage.
- Validate that layered phishing protections are enabled and monitored.
- Train analysts to recognize invisible-character obfuscation as a phishing signal.
- Watch for finance-themed lure campaigns and unusual weekday-volume patterns.
- Revisit email security controls to ensure they normalize or inspect hidden Unicode content where possible.
As attackers adapt AI-era evasion methods for email, defenders should update hunting strategies now rather than wait for these techniques to become standard practice.
Need help with Security?
Our experts can help you implement and optimize your Microsoft solutions.
Talk to an ExpertStay updated on Microsoft technologies