Skip to content
News

ASCII Smuggling: Spammers Adopt AI Attack to Beat Filters

ASCII smuggling, a technique first used to hide malicious prompts in attacks on AI agents, is now being used by spammers to slip past the filters that email platforms rely on to flag unwanted mass messages. The method rose to prominence two years ago as a way to make prompt injection attacks...

ASCII Smuggling: Spammers Adopt AI Attack to Beat Filters
ASCII smuggling, a technique first used to hide malicious prompts in attacks on AI agents, is now being used by spammers to slip past the filters that email platforms rely on to flag unwanted mass messages. The method ro

ASCII smuggling, a technique first used to hide malicious prompts in attacks on AI agents, is now being used by spammers to slip past the filters that email platforms rely on to flag unwanted mass messages.

The method rose to prominence two years ago as a way to make prompt injection attacks stealthier. Rather than embedding malicious instructions in ordinary text, attackers render them using a special range of Unicode tags. For instance, the tag point U+E0041 mirrors “A,” while U+E0061 mirrors “a.” The block of 128 tags reproduces a portion of the American Standard Code for Information Interchange almost exactly, with one crucial difference: the characters are readable by computers but nearly invisible to humans by design. Large language models detect the hidden instructions, but the person reading the email sees nothing.

From Hiding Prompts to Dodging Spam Filters

The same property that makes these characters ideal for smuggling instructions into a model also makes them effective for obfuscating keywords before a filter can evaluate them. As Microsoft put it, the intent is inverted but the mechanism is similar, and the recipient’s suspicions are never raised.

Earlier this year, Microsoft recorded a sharp surge in spam using the approach. Starting on a single day in early February, ASCII smuggling signatures detected by Microsoft Defender for Office jumped from roughly 21,000 per day to more than 1.3 million. Within four days, detections climbed to 2.5 million. The flood continued for months before dropping off sharply in mid-May.

How Spammers Break Up Trigger Words

Spammers are inserting invisible Unicode characters to evade filters that scan for specific text, including dollar amounts and common words such as “credit” and “term” that frequently appear in mass campaigns. By sprinkling hidden characters into the middle of a word like “funding,” a filter may read “fun” and “ding” separately, while the recipient still sees the intact word “funding.”

Camouflaging trigger words with special text is not a new tactic. For decades, spammers have used zero-width spaces and non-breaking spaces to accomplish similar goals. Such characters can defeat searches that match a literal string and can change the byte sequence that regular-expression filters look for.

The likely reason spammers turned to hidden Unicode tags is that many spam filters had not yet been programmed to detect them, giving the technique a window of effectiveness against defenses tuned for older evasion methods. Microsoft tracked daily Unicode-tag signature hits on finance-themed sender domains between February 9 and June 18, 2026, documenting the rise and eventual decline of the campaign.

Source
Image: arstechnica.com

The US tech briefing

Smartphones, AI, computing and deals — the essential stories without the noise.

Mailing provider can be connected when your US list is ready.

Shop Amazon Tech Deals Shop Amazon Tech Deals