Skip to content
Auto-CTI
Back to today
NEW HIGH C3

Phishing Campaign Sends Millions of Emails Using Invisible Unicode to Evade Filters

C The Hacker News ·

Admiralty grading (A–F · 1–6)

Source reliability

  • A Completely reliable
  • B Usually reliable
  • C Fairly reliable
  • D Not usually reliable
  • E Unreliable
  • F Cannot be judged

Information credibility

  • 1 Confirmed
  • 2 Probably true
  • 3 Possibly true
  • 4 Doubtful
  • 5 Improbable
  • 6 Cannot be judged

NATO Admiralty (AJP-2.1) grades confidence, independent of the risk score. Cross-source corroboration isn't tracked for non-CVE news, so single-source items are capped at a lower credibility number; a low number does not imply low quality.

Key insight

Attackers use invisible Unicode characters to split financial lure words and bypass modern email filters,representing an evolution of AI-era evasion techniques into large-scale traditional phishing campaigns.

Description

A phishing campaign sends millions of emails using invisible Unicode tag characters (ASCII Smuggling) to bypass email filters. Attackers split financial lure words such as 'funding' with invisible characters to prevent filter parsing. The technique adapts AI-era prompt-injection evasion methods for traditional phishing. The campaign emerged in February 2026 and reaches peak volumes of 1,2.37 million messages per weekday, peaking on February 26, 2026. This demonstrates how AI-focused security evasion techniques are being adapted into large-scale phishing operations.

Risk score

20
cvss base
0.00
kev bonus
0.00
epss bonus
0.00
poc bonus
15.00
raw before weight
15.00
industry weight
1.21
freshness factor
0.60
exploitability factor
1.00
days old
6.00
vendor mismatch penalty
0.00

Path: operational

ESC