Attackers conceal phishing lures using invisible Unicode characters

Attackers conceal phishing lures using invisible Unicode characters
Microsoft says threat actors used ASCII smuggling with invisible Unicode tag characters to hide finance-themed phishing content and evade email security filters. The campaign peaked at up to 2.37 million daily messages and is still active, prompting advice to normalize or strip invisible code points before detection and AI processing. #Microsoft #ActiveCampaign #DefenderforOffice365

Keypoints

  • Attackers used invisible Unicode characters to split suspicious words in phishing emails.
  • The technique helped evade filters that rely on keywords and signatures.
  • Microsoft observed a finance-themed campaign reaching 2.37 million daily messages.
  • Defender still blocked over 99% of the messages using other security signals.
  • Microsoft recommends normalizing Unicode tag characters before detection and AI processing.

Read More: https://www.bleepingcomputer.com/news/security/attackers-conceal-phishing-lures-using-invisible-unicode-characters/