MobbleOpen in Mobble ⇢
Technology · Cybersecurity · published 2026-09-06 · via BleepingComputer

Phishing campaigns use invisible Unicode to bypass email filters

Image via BleepingComputer
Image via BleepingComputer

Threat actors are using ASCII smuggling with invisible Unicode characters to hide finance-related keywords in phishing emails. Microsoft detected a large-scale campaign peaking at 2.37 million daily messages, with over 99% caught by Defender. The technique splits words like "funding" to evade word-list-based filters.

Expanded Detail

The campaign exploited the Unicode Tags block to insert hidden characters within financial terms like "capital" and "credit," effectively splitting them to bypass keyword-based scanning. Microsoft's telemetry showed the operation ran for roughly three months, peaking at 2.37 million messages daily in late February before tapering off in mid-May.

The phishing emails were distributed through the legitimate ActiveCampaign marketing platform, using 148 finance-themed sender domains. While the obfuscation worked, Microsoft's Defender still blocked over 99% of messages by analyzing sender reputation and infrastructure. ActiveCampaign confirmed its moderation flags heavy use of invisible Unicode as suspicious.

Context

This technique underscores a shift toward evading static defenses. Organizations relying solely on keyword-based filters could face higher exposure, while users may be tricked by seemingly legitimate financial offers. The abuse of a trusted marketing platform complicates sender verification. Furthermore, as AI assistants process email content, hidden Unicode could potentially trigger prompt-injection attacks, impacting automated workflows and decision-making. This suggests that robust normalization and behavioral analysis are becoming essential for comprehensive cybersecurity.

Expanded detail and Context are AI-generated analysis; the linked article remains the authoritative source.
Read the full article at BleepingComputer →
Related stories
Spammers Adopt Invisible Unicode Technique to Evade Email Filters · Cybersecurity
This summary is AI-generated and original to Mobble; the linked article is the authoritative source. Original headline: “Attackers conceal phishing lures using invisible Unicode characters.” Browse more stories.