• Hackers are using 'invisible' Unicode characters to sneak phishin

    From TechnologyDaily@1337:1/100 to All on Mon Sep 7 14:30:22 2026
    Hackers are using 'invisible' Unicode characters to sneak phishing lures into emails

    Date:
    Mon, 07 Sep 2026 13:20:00 +0000

    Description:
    A technique used in prompt injection attacks has made it into phishing, Microsoft has warned.

    FULL STORY ======================================================================Copy link Facebook X Whatsapp Reddit Pinterest Flipboard Threads Email Share this article 0 Join the conversation Follow us Add us as a preferred source on Google Newsletter Subscribe to our newsletter Microsoft reports phishing campaign using ASCII smuggling to bypass spam filters Attackers insert invisible characters into keywords, tricking filters and AI agents Defenders should normalize Unicode tags and flag unexpected invisible code points as suspicious Cybercriminals are using the ASCII smuggling technique to make
    sure phishing emails pass security filters and land in peoples inboxes, experts have warned.

    ASCII is a character encoding standard that turns characters and words humans can read into numeric values that computers can understand. It can also be used to create characters that arent even displayed on the screen
    (essentially invisible ones) but can still be read by the machine. In a new report , security researchers from Microsoft found crooks are abusing this fact to distribute phishing emails. Most email providers offer solutions that filter out spam emails. These filters look for certain keywords and phrases, such as funding, credit, loan, and similar, and automatically send such
    emails to the spam folder. Latest Videos From TechRadar Watch full video
    here: Ongoing campaign By adding a set of invisible characters in the middle of these keywords, the attackers can break them apart and thus confuse the filters.

    While the human sees the word funding in their email, the security solution
    is seeing something like fun[a long string of characters]ding. This technique has been adopted from prompt injection attacks, where crooks would use ASCII smuggling to deliver malicious and invisible prompts in the emails. You may like HP warns hackers are turning popular remote access tools into dangerous, stealthy backdoors Microsoft login pages are being abused as hackers try and lure in unlucky victims Devious phishing campaign hijacks a genuine Meta business feature to send scam emails as they really do come from Meta's own address

    Therefore, when a victim asks their AI agent to summarize the email, it ends up working on a prompt that could be anything from extracting sensitive data, to deploying malware .

    Microsoft is saying the campaign has been ongoing for months, and while it peaked in February 2026 with more than 2.3 million emails every day, and has been in decline ever since, it remains active to this day. In early February, Microsoft observed a cluster of almost 150 sender domains, all themed around finance. These domains accounted for almost all (96%) of all the spam emails Defender for Office 365 flagged under ASCII smuggling. Are you a pro? Subscribe to our newsletter Sign up to the TechRadar Pro newsletter to get
    all the top news, opinion, features and guidance your business needs to succeed! Contact me with news and offers from other Future brands Receive email from us on behalf of our trusted partners or sponsors By submitting
    your information you agree to the Terms & Conditions and Privacy Policy and are aged 16 or over.

    Defending sounds relatively simple, though. IT teams should normalize Unicode tag characters and other invisible code points before applying any keyword detection. They should also consider all unexpected tag-block characters as suspicious.

    Via BleepingComputer The best antivirus for all budgets Our top picks, based on real-world testing and comparisons

    Read our full guide to the best antivirus 1. Best overall: Bitdefender Total Security 2. Best for families: Norton 360 with LifeLock 3. Best for mobile: McAfee Mobile Security Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds.



    ======================================================================
    Link to news story: https://www.techradar.com/pro/security/hackers-are-using-invisible-unicode-cha racters-to-sneak-phishing-lures-into-emails


    --- Mystic BBS v1.12 A49 (Linux/64)
    * Origin: tqwNet Technology News (1337:1/100)