September 25, 2026 - 6 min read

By PhishClean Research Team

Invisible Characters, Real Phishing: Microsoft Finds ASCII Smuggling Used to Slip Past Email Filters

An email says "funding" and you read "funding". The spam filter reads "funding" with invisible characters between the letters, so its keyword match fails. Microsoft has now seen this trick, first described in AI security research, used in a large phishing campaign.

Microsoft Defender for Office 365 researchers described the campaign in early September 2026. The attackers put invisible Unicode "tag" characters inside financial lure words. Microsoft's summary: "The words still looked normal to recipients, but the altered underlying text could defeat exact keyword matches."

What ASCII smuggling is

Unicode has a block of "tag" characters that most fonts don't display at all. Security researchers first used them to hide instructions inside text given to AI models, since the model reads the hidden text but a human reviewer can't see it. Attackers have now pointed the same idea at email filters. Any system that looks for exact strings such as "funding", "loan approved" or "invoice" sees a different sequence of characters from the one the reader sees.

How big the campaign was

Microsoft said more than 99% of the messages were still caught by other Defender protections, such as reputation checks, sender authentication and machine-learning models. The invisible characters beat one layer, not the whole stack. Its advice to defenders is to normalise invisible Unicode before applying content signatures, and to test how their filters handle tag characters.

Each layer of defence has blind spots. A trick that fools a keyword filter won't fool a check that looks at where the link actually leads and what the page asks you to type.

What this means for you

The lesson isn't about Unicode. Any single check can be engineered around. Email filters look at text, and attackers change the text. So the last decision rests with the page you land on and what it asks you for. A "funding application" that wants your revenue, credit score and bank details on a domain you have never heard of is suspicious however clean the email looked.

What we look at instead

PhishClean doesn't read your email. It looks at links and pages in your browser, which is the layer this campaign didn't touch. Hover over a link and it tells you where the link really goes. Open the page and it checks for lookalike domains, forms that send data to a different site, and other signs of a harvesting page. All of it runs locally.

Sources

The page is where the attack has to show itself

PhishClean checks every link and page locally, the layer that invisible-character tricks don't touch.

Install PhishClean Free

Last updated:

Share This Guide

If this helped, share it with someone who would benefit from it, or subscribe for new browser-security guides from PhishClean.