Skip to content
Auto-CTI
Back to all deep dives
MICROSOFT SECURITY BLOG

ASCII smuggling crosses over from AI prompt injection to phishing evasion

HIGH phishing email-evasion unicode-smuggling defender-for-office-365

Strategic summary

The report describes how the ASCII smuggling technique, originally known from AI prompt injection attacks, is now being used in phishing campaigns to evade email filters. Attackers use invisible Unicode tag characters to hide parts of words such as 'funding', so filters cannot detect them while recipients read the text normally. Microsoft observed a sharp increase in such attacks starting on February 9, 2026, which lasted for about three months. Most messages were detected by layered protection mechanisms, not by a single signature.

Key findings

  • Attackers use invisible Unicode tag characters from the block U+E0000 to U+E007F to obfuscate keywords such as 'funding' and bypass email filters.
  • The ASCII smuggling technique originates from AI prompt injection research and is now being used in phishing campaigns.
  • Microsoft telemetry shows a sharp increase in such attacks starting on February 9, 2026, lasting about three months.
  • Most messages were detected by layered protection mechanisms, not by a single Unicode-based signature.
  • The invisible characters are not visible to humans but are processed by software such as email filters or AI models.

Relevance for you

A high-volume phishing campaign is using invisible Unicode characters (ASCII Smuggling) to evade email filters and conceal financial lure keywords,a technique adapted from AI prompt injection research.

Risk score

20
cvss base
0.00
kev bonus
0.00
epss bonus
0.00
poc bonus
0.00
raw before weight
0.00
industry weight
1.10
freshness factor
0.60
exploitability factor
1.00
days old
6.00
vendor mismatch penalty
0.00

Path: operational

ESC