344
Productivity & Workflow355
Automation & Workflow225
Software Development251
Marketing & Growth192
AI Infrastructure & MLOps175
Writing & Content Creation203
Data & Analytics142
Photography & Imaging156
Design & Creative170
Customer Support132
Sales & Outreach125
Voice & Speech135
Education & Learning131
Operations & Admin87
Microsoft says spammers are hiding words inside invisible Unicode characters, a trick first popular in attacks on AI tools, to evade email spam checks.
In short: Spammers are now using “ASCII smuggling,” a way to hide invisible text inside emails, to sneak past spam and phishing filters.
ASCII smuggling first became known as a method for hiding “prompt injections,” which are secret instructions meant to trick AI assistants into doing something unsafe. The same hiding method is now showing up in regular spam emails.
The trick uses a special part of Unicode, which is the big catalog of characters used by computers for text in many languages. In this case, spammers use a set of Unicode “tag” characters that computers can read but people almost never see. It is like writing a message in ink that a machine can detect, while a human sees a normal sentence.
Microsoft says it saw a major spike in this activity earlier this year. Microsoft Defender for Office detections went from about 21,000 per day to more than 1.3 million in early February. Within four days, detections reached 2.5 million. The wave lasted for months, then dropped sharply in mid-May.
Spammers use the invisible characters to break up “trigger” words that filters look for, such as “credit,” “term,” or dollar amounts. For example, a message can look like it says “funding” to you, but a filter might read it as “fun” and “ding” because invisible characters are inserted in the middle.
Email services will likely update their filters to spot these invisible characters, but spammers often move on to new tricks once old ones are blocked. Microsoft also noted that some modern filters rely on models that split text into pieces before checking it, and hidden characters can confuse that step. Expect more defensive updates, and more experiments by spammers to dodge them.
Source: Arstechnica