Microsoft is warning about a high-volume phishing campaign that uses invisible Unicode characters to bypass email security filters and hide financial lure terms from detection.
The campaign uses a technique known as ASCII smuggling, where non-rendering Unicode characters are inserted into otherwise normal-looking text. While the characters are invisible to recipients, email security tools or AI systems may process them as part of the message.
Microsoft said attackers are using the technique differently from its earlier AI-related applications. Instead of hiding instructions from people while exposing them to AI models, the attackers are inserting invisible characters into financial terms such as “funding” to prevent email filters from recognizing the words.
The characters most commonly abused in the campaign come from the Unicode Tags block, covering U+E0000 to U+E007F. The block contains hidden versions of printable ASCII characters and was originally designed for language tagging but is now largely deprecated.
Microsoft said the phishing activity first appeared in early February 2026 and entered a high-volume phase that lasted for roughly three months before sharply declining after May 15. The campaign followed a weekly pattern, with activity dropping significantly on weekends and returning at full scale on Mondays.
Daily weekday volumes were estimated at between 1 million and 2.37 million messages, with the campaign reaching its highest level on February 26. Microsoft said the activity appears connected to a broader phishing operation that abused the ActiveCampaign marketing and automation platform to distribute thousands of AI-generated emails targeting Small Business Administration loan applicants.
The broader campaign was previously detailed by Fortra’s Intelligence and Research Experts team in September 2025. It focused on collecting detailed business and financial information that could potentially be used for more targeted spear-phishing attacks.
In the latest activity, attackers inserted invisible Unicode characters inside common financial keywords. For example, the word “funding” could be split by an invisible character so that it still appears as “funding” to a recipient, while security systems searching for the exact continuous word may fail to detect it.
Microsoft said this works because some detection systems do not account for invisible Unicode characters placed between individual letters. Other systems may remove or normalize the characters before processing the message, allowing the word to remain readable.
The technique itself is not new, as attackers have previously used invisible and look-alike characters in phishing and homoglyph attacks. What stands out in this campaign is the use of the Unicode Tags block and the scale of the operation, which reached millions of messages per day.
The campaign used hundreds of disposable domains designed around financial themes, with messages impersonating business loans, lines of credit and advance-funding services. The emails were also routed through ActiveCampaign, with links passing through the platform’s click-tracking domains.
ActiveCampaign said it has tested its content-moderation systems against messages containing invisible Unicode characters and found that they receive the same moderation verdict as their unobfuscated versions. The company also said heavy use of the technique is treated as a suspicious signal.
If this article helped you, please consider supporting our work. Every small contribution keeps Abijita.com independent and running.
Microsoft warned that abuse of legitimate marketing platforms can make phishing campaigns harder to detect because attackers can benefit from established IP reputations and authentication associated with trusted services. This can make malicious traffic appear more similar to legitimate marketing emails and complicate reputation-based filtering.
Microsoft Warns of Phishing Campaign Using Invisible Unicode Characters





