Once popular for attacking AI, ASCII smuggling is embraced by spammers
Spammers are using ASCII smuggling, a technique previously used for AI prompt injection, to bypass email security filters. By inserting invisible Unicode characters into text, attackers can split keywords like "funding" to hide phishing lures from automated detection systems. Microsoft identified this shift after a prompt injection detector flagged a phishing campaign. This transition demonstrates how AI-specific vulnerabilities are being repurposed for traditional social engineering attacks, allowing millions of malicious emails to reach targets by exploiting blind spots in AI-driven email security.
Listen to Live Briefing
Real-time synthesized voice briefing · Live Feeds Desk
- ✓ ASCII smuggling has transitioned from AI prompt injection attacks to phishing and spam campaigns.
- ✓ Attackers use invisible Unicode characters to conceal phishing lures and evade filters.
- ✓ Microsoft discovered a phishing campaign using these techniques via a prompt injection detector.
What changed
Phishing campaigns are now applying AI prompt injection techniques to split words and evade email filters.
Live updates
-
Spammers adopt ASCII smuggling to evade phishing filters
Spammers are using ASCII smuggling, a technique previously used for AI prompt injection, to bypass email security filters. By inserting invisible Unicode characters into text, attackers can split keywords like "funding" to hide phishing lures from automated detection systems. Microsoft identified this shift after a prompt injection detector flagged a phishing campaign. This transition demonstrates how AI-specific vulnerabilities are being repurposed for traditional social engineering attacks, allowing millions of malicious emails to reach targets by exploiting blind spots in AI-driven email security.
Why it matters
ASCII smuggling uses non-printing characters to hide data from machine readers while remaining visible to humans. It was originally developed to manipulate AI models via prompt injection. The shift to email phishing shows a broadening of the attack surface for invisible character exploits.
What is confirmed
- ASCII smuggling has transitioned from AI prompt injection attacks to phishing and spam campaigns.
- Attackers use invisible Unicode characters to conceal phishing lures and evade filters.
- Microsoft discovered a phishing campaign using these techniques via a prompt injection detector.
Still unconfirmed
- A phishing campaign has sent millions of emails using invisible Unicode.
- Attackers are specifically using the technique to split the word funding in spam.
What to watch next
- Updates from email security providers on new detection methods for invisible Unicode
- Evidence of other AI-specific exploits migrating to traditional phishing
confidence 90%Sources used for this update (9)
- Ars Technica — Once popular for attacking AI, ASCII smuggling is embraced by spammers
- Microsoft — ASCII smuggling crosses over from AI prompt injection to phishing evasion
- The Hacker News — Phishing Campaign Sends Millions of Emails Using Invisible Unicode to Evade Filters
- The Register — ASCII smuggling isn't just an AI security risk
- DevPro Journal — Text salting exposes a blind spot in AI email security
- The New Stack — Microsoft built a prompt injection detector. Then it caught a phishing campaign instead.
- The Next Web — ASCII smuggling crossed over from AI attacks to spam
- BleepingComputer — Attackers conceal phishing lures using invisible Unicode characters
- thenextweb.com — An AI hacking trick is now being used to split the word ‘funding’ in spam
Community Sentiment: How do you assess this situation?
Voice your perspective · Real-time aggregated sentiment from the Live Feeds community