Phishing Campaign Sends Millions of Emails Using Invisible Unicode to Evade Filters

Microsoft has issued a warning about a widespread phishing campaign that is utilizing invisible Unicode tag characters to evade email filters.

According to the Microsoft Security Research team, the attacker is using these characters to split financial lure words like ‘funding’ to outsmart email filters. This technique has been observed in phishing and spam campaigns since early February 2026.

ASCII Smuggling involves hiding messages or instructions inside seemingly harmless text using invisible Unicode characters. While these characters are not displayed to human users, they can be detected by email filters or AI language models, leading to potential security risks.

Microsoft revealed that the phishing campaign leveraging ASCII smuggling peaked on February 26, 2026, with weekday message volumes reaching up to 2.37 million. The campaign targeted Small Business Administration (SBA) loan applicants through AI-generated phishing emails.

The phishing operation, as disclosed by the Fortra Intelligence and Research Experts (FIRE) team, focused on collecting detailed business and financial information for future spear-phishing attacks. The attackers used ActiveCampaign’s AI-powered marketing automation features to create convincing phishing websites tailored to different domains.

The latest wave of phishing emails employs invisible tag characters to obfuscate common financial keywords, making it difficult for email filters to detect malicious content. The use of Unicode Tags block characters in this campaign sets it apart from traditional phishing techniques.

The campaign utilizes disposable sender domains related to finance themes, such as business loans and advance funding, to deceive recipients. These emails are sent through ActiveCampaign, with all outbound links routed through click-tracking domains.

ActiveCampaign has stated that its content moderation systems can detect emails containing invisible Unicode characters and treat them as suspicious. However, attackers leveraging reputable marketing platforms like ActiveCampaign can evade reputation-based filtering.