Historical intelligence backfill. This assessment covers reporting originally published on 2026-09-03 and was added to the RWP archive on 2026-09-07.

Daily Top · Identity

ASCII smuggling left the LLM paper and showed up as invisible Unicode in 2.3 million phish mails

Microsoft saw Unicode tag characters split words like "funding" so filters missed them — a hunting signature jumped from ~21k hits on 8 February 2026 to 1.3 million the next day.

RWP Ventures · 2026-09-07 · event 2026-02-09 · 1 min read · priority 7.5

Bottom line up front

CONFIRMED Microsoft's 3 September 2026 note: high-volume phishing used invisible Unicode tag characters — the same "ASCII smuggling" trick from prompt-injection papers — to break financial lure words so regex/token filters would not see "funding." Defender for Office 365 hunting signature: ~21,000 hits 8 February 2026, more than 1.3 million on 9 February, peak over 2.3 million on 11 February, weekday-elevated ~three months, sharp drop after 15 May. Most mail was still caught by layered detections, not the Unicode signature alone. Technique bounded those dates; the broader campaign existed before and after without smuggling.

Historical backfill of 3 September 2026 reporting; added 7 September 2026.

What happened

AI-security research leaked into crimeware. Insert zero-width/tag characters inside a word. Humans see the lure; some scanners see fragments.

Why it mattered

If your phish rules are string-match on English, Unicode is a free bypass. Layered mail defense is why Microsoft says volume did not equal inbox success.

Who / what was affected

Microsoft telemetry, not a named victim sector. OT not applicable.

Technical context

Normalize Unicode before tokenizing. Hunt tag characters (U+E0001–U+E007F class) in subjects/bodies. Do not rely on one Unicode YARA.

Exploitation / threat status at the time

CONFIRMED Microsoft volume and dates.

ASSESSED copycat of AI-research technique, not a new APT.

What defenders should have done

  1. Unicode normalization in mail pipelines.
  2. Do not retire the signature after 15 May — the campaign continued without it.
  3. Treat "funding" fragments as the same lure.

RWP assessment

Confidence: High on telemetry. This is filter-evasion fashion, not a 0-day.

Defensive actions

  1. Normalize then detect.
  2. Keep layered Defender/equivalent policies.
  3. Brief IR that "clean-looking English" can still be smuggled.

Sources

  1. Microsoft — ASCII smuggling crosses over from AI prompt injection to phishing evasion
  2. Microsoft — Email threat landscape Q1 2026
  3. Microsoft — Email threat landscape Q2 2026