ASCII smuggling isn’t just an AI security risk

← Back to the feed

ASCII smuggling isn’t just an AI security risk

The Register · 4 hours ago

Microsoft has revealed that fraudsters have adapted ASCII smuggling, a technique previously associated with hiding malicious prompts for AI models, into a large-scale email phishing campaign. Instead of embedding hidden instructions for an AI assistant, attackers inserted invisible Unicode tag characters within financial keywords, such as splitting "funding" into "fun[invisible character]ding", to evade keyword and signature-based content filters. The discovery highlights how attack techniques emerging from AI security research can quickly migrate into established threats such as phishing, underscoring the need for defenders to monitor cross-domain risks.

Microsoft first spotted the technique on 8 February, with around 21,000 flagged messages that jumped to over 1.3 million the following day, later peaking at more than 2.37 million messages on 26 February. The campaign, largely originating from roughly 150 finance-themed sender domains, followed a distinctive weekday-only pattern before gradually declining through March and dropping sharply after 15 May, with residual activity into mid-June. Microsoft recommends that organisations strip or normalise invisible Unicode characters before applying keyword or regex-based filtering, and watch for behavioural indicators such as bulk sending from disposable finance-themed domains on a strict weekday schedule.

  • Phishers repurposed AI-targeted ASCII smuggling to evade email filters
  • Campaign peaked at 2.37 million messages in late February
  • Microsoft urges stripping invisible Unicode characters before keyword scanning

AI Technology

Read the full article at the source →