News

Microsoft tracks ASCII smuggling in phishing mail

Microsoft Security, using Defender for Office 365 telemetry, tracked phishing that splices Unicode Tags (U+E0000 to U+E007F) into finance lure words. Signature hits jumped from about 21,000 on 8 February 2026 to more than 1.3 million the next day, and weekday volume peaked at 2.37 million on 26 February.

Microsoft tracks ASCII smuggling in phishing mail

Microsoft Security published a research blog on 3 September 2026 from Defender for Office 365 prompt-injection hunting. The writeup tracks a phishing-evasion technique. It is not a CVE, not a patch advisory, and not a finding that ActiveCampaign is malware.

Attackers reused the Unicode Tags block (U+E0000 to U+E007F), including TAG SPACE U+E0020, to split finance lure words such as "funding." Humans still read the word. Keyword, regex, and tokenizer checks that do not normalize first can miss it.

Signature hits jumped from about 21,000 on 8 February 2026 to more than 1.3 million on 9 February. Weekday volumes then ran from 1 million to 2.37 million, with the 2.37 million peak on 26 February. The cadence was weekday on and weekend off. The high-volume phase dropped after 15 May, with residual hits into mid-June.

Roughly 150 finance-themed disposable sender domains drove about 96 percent of that signature cluster. On 9 February alone, guardiangrowthfunding.com logged 30,442 hits. The brand names were recombinations of a 28-token finance vocabulary. Clicks went through ActiveCampaign tracking hosts (acemlnd.com and activehosted.com), while envelope senders used em-, acems, and emsd shapes.

About 92 percent of measured volume came from 173.236.20.0/24. Microsoft treats that block as shared platform egress and corroboration, not a standalone indicator. ActiveCampaign said invisible Unicode gets the same moderation verdict as the unobfuscated text, and that heavy use is itself a suspicious signal.

Microsoft ties this phase to a longer Fortra-documented, ActiveCampaign-relayed SBA-themed campaign that existed before Unicode tags and continued after the tags dropped. Layered Defender for Office 365 controls flagged the majority of messages without relying only on the Unicode signal. The company says over 99 percent of those hits came from other layers.

Defense is mechanical. Strip or fold the tag block and other invisible characters before any keyword or regex match. Treat leftover tag-block characters as an anomaly, excluding known flag-emoji sequences. The same normalize-first step also cuts prompt-injection risk when mail is later ingested by an assistant.

Inbox evasion is a different job from rushing a Chrome V8 in-the-wild patch. It is closer to the defender-capacity problem OpenAI's Daybreak credits try to fund, and it is not a vendor-cloud dump like the Aesto Health notice. The technique crossed over from AI prompt-injection research, the same lane as OpenAI's Hugging Face incident report.

Email-security, SOC, and Microsoft 365 admins should strip U+E0000 through U+E007F before keyword rules this week, alert on weekday spikes of tag-block characters from finance-vocabulary domains, and confirm OCR or visual-text paths are on so a tokenizer cannot be split.

Cyberpresso: daily cyber & AI brief

Free daily newsletter, read in 5 minutes.

Subscribe free