Microsoft Security Blog published the article “ASCII smuggling crosses over from AI prompt injection to phishing evasion.” The article explains how invisible Unicode characters can bypass email filters.

The ASCII smuggling technique has moved from hiding instructions for AI models to evading phishing email filters. Invisible Unicode characters are used to obfuscate words.

Words are obfuscated before email filters parse them.

Claim check:

  • Microsoft Security Blog published the Threat intelligence article “ASCII smuggling crosses over from AI prompt injection to phishing evasion,” which explains how invisible Unicode characters can bypass email filters. (confirmed by the primary source: evidence; «Threat intelligence September 3 17 min read ASCII smuggling crosses over from AI prompt injection to phishing evasion Invisible Unicode characters popularized for hiding instructions from AI models are now being used to obfuscate words before email filters parse them.»)
  • The ASCII smuggling technique has moved from hiding instructions for AI models to evading phishing email filters. (confirmed by the primary source: evidence; «ASCII smuggling crosses over from AI prompt injection to phishing evasion»)
  • Invisible Unicode characters are now used to obfuscate words before email filters parse them. (confirmed by the primary source: evidence; «Invisible Unicode characters popularized for hiding instructions from AI models are now being used to obfuscate words before email filters parse them.»)
  • The campaign used Unicode tag characters in the U+E0000–U+E007F range, which do not appear in most interfaces but change the string processed by software. (not found in the primary source: evidence)
  • Attackers inserted these characters into the words “funding,” “loan,” and “credit” so filters would not find an exact match. (not found in the primary source: evidence)
  • The hunting signature for ASCII smuggling matched about 21,000 messages before the campaign, then more than 1.3 million, and more than 2.3 million messages two days later. (not found in the primary source: evidence)
  • Recipients saw ordinary offers of business loans and credit lines despite the hidden characters in the email bodies. (not found in the primary source: evidence)
  • Inserting an unexpected Unicode character into a word changes text tokenization in NLP systems and can therefore hide malicious content from AI systems. (not found in the primary source: evidence)

Publications:

Primary sources:

score 77.5 · kind incident · revision 1 · stories st-19cdpl0