Phishing Campaign Uses AI Evasion Tactic to Bypass Email Filters
Microsoft detected 2.37 million messages using invisible Unicode characters to split keywords and evade detection systems.

Attackers Repurpose AI Security Technique for Email Fraud
A phishing operation discovered by Microsoft demonstrates how techniques developed for attacking AI systems are migrating into conventional cybercrime. The campaign deployed ASCII smuggling—a method typically used to hide malicious instructions from AI models—to evade email security filters by inserting invisible Unicode characters into financial keywords.
The attack peaked in late February with more than 2.37 million messages in a single day, according to Microsoft security researchers Noam Kochavi and Sarah Wolstencroft. The campaign maintained elevated volumes on weekdays through May before gradually declining by mid-June.
Rather than targeting AI assistants, the attackers inserted Unicode tag spaces between letters in words like "funding" to break them into fragments that would slip past keyword matching systems. A human reader would see normal text, but signature-based filters searching for specific terms would fail to detect them.
Why It Matters
This campaign signals a concerning trend: as security researchers develop defenses against AI-specific attacks, threat actors are adapting those same techniques for traditional fraud schemes. Organizations relying solely on keyword-based email filtering face a new evasion method that requires updated detection approaches. The scale—millions of messages from approximately 150 finance-themed domains—suggests well-resourced operations are already implementing these tactics at volume.
Campaign Characteristics and Timeline
Microsoft first identified the ASCII-smuggling signature in early February, flagging roughly 21,000 messages on February 8. The volume exploded to more than 1.3 million the following day. The campaign exhibited two distinctive patterns: strict weekday activity with complete silence over weekends, and a gradual decline after its initial intensity.
Weekday volumes ranged from 1 to 2.37 million messages during the first phase, peaking on February 26. By late March, daily volumes had dropped to approximately 80 percent lower than peak levels. A sharp decline occurred after May 15, though smaller spikes continued through at least mid-June.
Defense Recommendations
Microsoft's threat hunters emphasize that defenders must ensure normalization and tokenization pipelines handle tag characters consistently. Content evaluated by keyword, signature, or regex logic should have invisible and non-rendering Unicode code points stripped or normalized before matching occurs.
The same controls that prevent this email evasion technique can also protect AI assistants that process email content from ASCII-smuggling attacks designed for prompt injection.
Behavioral detection offers another defense layer. The campaign's distinctive characteristics—bulk volume from disposable finance-themed domains operating on a strict weekday schedule—provide high-confidence indicators for identifying similar operations. A sudden spike in tag-block characters concentrated among financial senders with weekly on-off patterns should trigger investigation.
The findings were first reported by Microsoft researchers in a security blog post published Thursday.
This is an original analysis by the Omega editorial team. Source reporting: AI Watch.
Want systems like this working for your business?
Book a Call