Skip to content
Auto-CTI
Back to today
NEW HIGH B3

ASCII smuggling crosses over from AI prompt injection to phishing evasion

B Microsoft Security Blog ·

Admiralty grading (A–F · 1–6)

Source reliability

  • A Completely reliable
  • B Usually reliable
  • C Fairly reliable
  • D Not usually reliable
  • E Unreliable
  • F Cannot be judged

Information credibility

  • 1 Confirmed
  • 2 Probably true
  • 3 Possibly true
  • 4 Doubtful
  • 5 Improbable
  • 6 Cannot be judged

NATO Admiralty (AJP-2.1) grades confidence, independent of the risk score. Cross-source corroboration isn't tracked for non-CVE news, so single-source items are capped at a lower credibility number; a low number does not imply low quality.

Key insight

A high-volume phishing campaign is using invisible Unicode characters (ASCII Smuggling) to evade email filters and conceal financial lure keywords,a technique adapted from AI prompt injection research.

Description

Attackers are currently running massive phishing campaigns with fake financial offers (business loans, credit lines, funding advances) using invisible Unicode tag characters (U+E0000-U+E007F) to fragment keywords. This technique disrupts tokenization and signature-matching behavior of email filters, making detection by traditional content filters more difficult. The campaign originates from disposable finance-themed domains. The technique is adapted from AI prompt injection research, demonstrating how AI security insights are being repurposed for classic phishing evasion.

Risk score

20
cvss base
0.00
kev bonus
0.00
epss bonus
0.00
poc bonus
0.00
raw before weight
0.00
industry weight
1.10
freshness factor
0.60
exploitability factor
1.00
days old
6.00
vendor mismatch penalty
0.00

Path: operational

ESC