Attackers conceal phishing lures using invisible Unicode characters
10 Articles
10 Articles
Invisible Unicode used to bypass phishing filters
Microsoft identified a large phishing campaign using ASCII smuggling to hide finance-related lure words with Unicode tag-block characters. Telemetry showed peaks of 2.37 million emails per day in late February 2026. A cluster of 148 sender domains...
ASCII smuggling crossed over from AI attacks to spam
For two years, invisible Unicode characters have been the neat trick of AI security research. You hide instructions inside them. A person sees nothing. A language model reads them and does as it is told. Microsoft has now found somebody using the same characters for something far less clever. They were splitting up the word […] This story continues at The Next Web
A phishing campaign reached 2.37 million e-mails one day, after the attackers used invisible Unicode characters.
Coverage Details
Bias Distribution
- 50% of the sources are Center
Factuality
To view factuality data please Upgrade to Premium











