Microsoft Warns of Phishing Campaigns Using Invisible Unicode Characters for Filter Evasion

Threat actors are leveraging ASCII smuggling techniques and invisible Unicode characters from the Tags block (U+E0000–U+E007F) to bypass email security filters in ongoing finance-themed phishing operations.

Microsoft threat researchers uncovered a high-volume phishing campaign that peaked at approximately 2.37 million daily messages in late February 2026. While the overall volume of malicious emails tapered off gradually following May 15, 2026, the underlying evasion tactic remains active across enterprise targets worldwide.

The campaign relies on inserting invisible Unicode characters directly into standard lure words related to finance, such as funding, capital, loan, advance, and credit. By fracturing words into formats like fun[invisible character]ding, attackers successfully evade conventional email filters that depend on static keyword lists to flag suspicious content.

Microsoft telemetry indicates that a cluster of 148 finance-themed sender domains powered roughly 96% of the messages flagged by Defender for Office 365 hunting logic on February 9. These deceptive messages were distributed using infrastructure associated with the legitimate ActiveCampaign email-marketing platform.

“The high-volume phase persisted for roughly three months after February 9 and dropped sharply after May 15, 2026,” explained Microsoft researchers regarding the observed campaign timeframe.

Following notification of the service abuse, ActiveCampaign stated that its moderation systems are configured to detect invisible Unicode characters analogously to unobfuscated text and evaluate heavy utilization as anomalous. Security analysts recommend that enterprise defenders strip or normalize Unicode tag characters prior to executing keyword, regular expression, or signature-based scans.

Leave a Reply

Your email address will not be published. Required fields are marked *