Phishing campaigns use invisible Unicode to bypass email filters

Threat actors are using ASCII smuggling with invisible Unicode characters to hide finance-related keywords in phishing emails. Microsoft detected a large-scale campaign peaking at 2.37 million daily messages, with over 99% caught by Defender. The technique splits words like "funding" to evade word-list-based filters.
The campaign exploited the Unicode Tags block to insert hidden characters within financial terms like "capital" and "credit," effectively splitting them to bypass keyword-based scanning. Microsoft's telemetry showed the operation ran for roughly three months, peaking at 2.37 million messages daily in late February before tapering off in mid-May.
The phishing emails were distributed through the legitimate ActiveCampaign marketing platform, using 148 finance-themed sender domains. While the obfuscation worked, Microsoft's Defender still blocked over 99% of messages by analyzing sender reputation and infrastructure. ActiveCampaign confirmed its moderation flags heavy use of invisible Unicode as suspicious.
This technique underscores a shift toward evading static defenses. Organizations relying solely on keyword-based filters could face higher exposure, while users may be tricked by seemingly legitimate financial offers. The abuse of a trusted marketing platform complicates sender verification. Furthermore, as AI assistants process email content, hidden Unicode could potentially trigger prompt-injection attacks, impacting automated workflows and decision-making. This suggests that robust normalization and behavioral analysis are becoming essential for comprehensive cybersecurity.