Once popular for attacking AI, ASCII smuggling is embraced by spammers

| Source: Ars Technica AI

Tags: ASCII-smuggling, prompt-injection, Unicode, Microsoft-Defender, spam, email-security, AI-security

A Unicode invisibility technique originally developed for LLM prompt injection attacks is now weaponized by spammers to evade email filters — Microsoft detected a spike from 21,000 to 2.5 million daily occurrences within four days in February 2026, making it one of the fastest-scaling spam evasion techniques on record.

Details

ASCII smuggling exploits a block of 128 Unicode 'tag' characters (range U+E0041–U+E007A) that mirror standard ASCII letters but are invisible to human readers while remaining fully readable by software. Originally used two years ago to embed hidden prompt injection instructions into emails processed by LLMs, the technique has been repurposed: spammers now use it to conceal spam trigger words from email content filters.\n\nMicrosoft Defender for Office 365 caught the transition in real time. Starting in early February 2026, ASCII smuggling signatures spiked from ~21,000 daily detections to 1.3 million in a single day, then hit 2.5 million within four days. The campaign ran for months before falling sharply in mid-May. Finance-themed sender domains — targeting keywords like 'funding,' 'credit,' and 'term' — were among the most active abusers.\n\nThe mechanism works by splitting visible keywords with invisible Unicode tags: a filter scanning for 'funding' reads 'fun' plus invisible characters plus 'ding' and finds no match. The user sees 'funding' normally. Microsoft notes the irony: 'The intent is inverted, but the mechanism is similar, and a user's suspicions are not raised.'\n\nThis story illustrates a recurring security pattern: techniques pioneered for AI attacks get industrialized by financially motivated actors. Security teams defending both AI pipelines and enterprise email now share the same attack surface.