Tech giant Microsoft has warned users about a major phishing campaign. In this cyberattack, threat actors (hackers) are using invisible Unicode tag characters to bypass email security filters. According to the Microsoft security research team, this technique exemplifies the new evasion tactics of the AI era, which are now being widely adopted in traditional phishing and spam attacks.
How are hackers evading email filters?
According to the Microsoft security research team, attackers are inserting invisible Unicode tag characters into emails—characters that are invisible to the human eye. These characters are used to split up financial lure words—such as "funding"—into separate segments. This makes it difficult for email filters to recognize the complete word, allowing the phishing email to slip past standard security checks.
Microsoft noted that in this instance, the invisible characters are not being used to hide instructions from the recipient, but specifically to break up financial lure words.
What are invisible Unicode characters?
Invisible Unicode characters are characters that exist within the text but do not appear in the standard user interface. In other words, while the text may look normal to a user reading the email, it contains hidden characters that can be read by backend systems or software. Consequently, they can be used to deceive security systems.
This technique is also linked to "ASCII smuggling," where invisible or non-rendering Unicode characters are used to hide additional messages or instructions within seemingly ordinary text.
Since the human user interface does not render these characters, the text appears completely normal to the recipient. However, email filters, software, or AI models can read these hidden characters while processing the content. This distinction opens up a new avenue for cybercriminals.
Surprisingly, this technique challenges more than just traditional email filters; it can also pose security risks for AI and Large Language Models (LLMs).
LLMs often struggle to reliably distinguish between instructions provided directly by a user and content found in third-party sources, such as emails, documents, or web pages.
Consequently, hidden content can be exploited for "prompt injection"—meaning an AI system could receive instructions that the user did not write directly or is entirely unaware of.
**Use of Unicode Tag Characters**
According to Microsoft, the most frequently abused Unicode range is the "Unicode Tags" block (U+E0000 to U+E007F). This block contains a sort of "shadow copy" of printable ASCII characters.
Originally created for language tagging, this Unicode block is now largely considered deprecated (obsolete). Cybercriminals exploit these characters to alter text that otherwise appears normal.
**How long has this phishing campaign been active?**
According to Microsoft, attacks utilizing this technique first emerged in early February 2026. Details regarding this campaign had previously been shared by the expert team at Fortra Intelligence and Research in September 2025.
Fortra noted that the campaign was distinguished by more than just the Unicode technique; it involved the large-scale use of credible-looking phishing websites that were rapidly generated using various illicit or impersonated domains. Phishing sites are being created rapidly using AI-powered tools
Fortra reported that threat actors were leveraging AI-powered marketing automation features—typically used for legitimate campaigns—to alter the design, content, and flow of phishing campaigns. This allows attackers to quickly create various websites and campaigns tailored to different fake or impersonated domains; essentially, it demonstrates that cybercriminals, not just legitimate businesses, can utilize AI and automation to make phishing campaigns more effective.
Why did Microsoft issue a warning?
Microsoft states that this trend highlights how evasion techniques associated with the AI era are now being adopted in traditional phishing and spam campaigns.
Previously, techniques like "invisible Unicode" were primarily discussed in the context of confusing AI models or executing attacks such as prompt injection. Now, these same methods are being used to bypass email filters. This makes it increasingly difficult for email security systems to detect phishing emails based solely on standard text patterns.
How can users stay safe?
To protect yourself from such phishing attacks, do not immediately click on links found in suspicious emails. Exercise extra caution with emails related to banking, payments, funding, account verification, or financial offers.
If an email contains a link, avoid clicking it; instead, verify the information by directly visiting the company's official website or app.
Additionally, do not trust an email simply because the text appears normal.
Disclaimer: This content has been sourced and edited from Amar Ujala. While we have made modifications for clarity and presentation, the original content belongs to its respective authors and website. We do not claim ownership of the content.
-
Maharashtra Dahi Handi festivities leave woman dead, 42 injured

-
‘Distortion Of History Continued Even After Independence,' Sitharaman Claims

-
Minimal is the new trend, these 4 types of veils will catch the eye with monochrome kurtis in Panchami-Sashthi.

-
Are pimples appearing again and again on the face? Make this easy face pack with neem and aloe vera

-
Bhindi To Chicken Leg: 6 Viral Samosa Variations To Try On World Samosa Day
