Phishing Campaign Sends Millions of Emails Using Invisible Unicode to Evade Filters

Phishing Campaign Sends Millions of Emails Using Invisible Unicode to Evade Filters
Microsoft says a high-volume phishing campaign is using invisible Unicode tag characters to split finance-related lure words and evade email filters, with the activity peaking at millions of messages per day. The campaign is tied to finance-themed sender domains and ActiveCampaign infrastructure, and it shows how AI-era evasion tactics can be reused in traditional phishing operations. #Microsoft #ActiveCampaign #UnicodeTags

Keypoints

  • Microsoft detected a high-volume phishing campaign using invisible Unicode tag characters.
  • The hidden characters split words like β€œfunding” to bypass keyword-based email filters.
  • The technique is known as ASCII smuggling and can also affect AI and parsing systems.
  • The campaign was linked to millions of messages per day and used finance-themed sender domains.
  • ActiveCampaign was used to relay the emails and route links through its tracking domains.

Read More: https://thehackernews.com/2026/09/phishing-campaign-sends-millions-of.html