Phishers adopt ASCII smuggling, a trick born in AI security research
Microsoft traced a campaign using invisible Unicode tag characters that peaked above 2.37 million messages in late February.

Evidence: Official disclosure. Security stories run only with a named disclosure or independent reporting behind them.
A technique developed to hide prompts from AI models has crossed into conventional email phishing. Microsoft uncovered a large campaign that used invisible Unicode tag characters, the core of what security researchers call ASCII smuggling, to slip past mail filters. The campaign peaked at more than 2.37 million messages in late February, stayed elevated on weekdays for the following three months, and gradually declined by mid-June. ASCII smuggling embeds characters that are invisible to human readers but still parsed by software. It is best known as a way to conceal malicious instructions intended for large language models, but the same invisibility works against filters that scan for suspicious text. Microsoft researchers Noam Kochavi and Sarah Wolstencroft wrote in a Thursday blog that as AI-era attack methods become better understood, threat actors may adapt them for traditional threats such as phishing and spam. They said the case shows how techniques from AI security research can quickly move into established attack ecosystems and argued defenders need to view emerging threats through a cross-domain lens. The Register and The Hacker News both covered the disclosure. For email security teams, the practical implication is that filters and detection rules should normalize or flag invisible Unicode ranges rather than assuming the technique only matters for AI systems.
Sources
- theregisterASCII smuggling isn
- The Hacker NewsPhishing Campaign Sends Millions of Emails Using Invisible Unicode to Evade Filters