
Phishing Goes Incognito: Invisible Unicode Tricks Evade Filters
Microsoft uncovered a massive phishing campaign that used invisible Unicode tag characters to hide content and split keywords, a form of ASCII smuggling that can bypass filters and extend beyond AI prompts into traditional email scams. The campaign peaked at 2.37 million messages in late February from finance-themed domains with weekday bursts and weekend lulls, and declined thereafter. Defenders are advised to normalize/tokenize to strip non-rendering Unicode points and monitor behavioral patterns like weekday-on/weekend-off activity.