Historical intelligence backfill. This assessment covers reporting originally published on 2026-09-03 and was added to the RWP archive on 2026-09-07.
ASCII smuggling left the LLM paper and showed up as invisible Unicode in 2.3 million phish mails
Microsoft saw Unicode tag characters split words like "funding" so filters missed them — a hunting signature jumped from ~21k hits on 8 February 2026 to 1.3 million the next day.
Bottom line up front
CONFIRMED Microsoft's 3 September 2026 note: high-volume phishing used invisible Unicode tag characters — the same "ASCII smuggling" trick from prompt-injection papers — to break financial lure words so regex/token filters would not see "funding." Defender for Office 365 hunting signature: ~21,000 hits 8 February 2026, more than 1.3 million on 9 February, peak over 2.3 million on 11 February, weekday-elevated ~three months, sharp drop after 15 May. Most mail was still caught by layered detections, not the Unicode signature alone. Technique bounded those dates; the broader campaign existed before and after without smuggling.
Historical backfill of 3 September 2026 reporting; added 7 September 2026.
What happened
AI-security research leaked into crimeware. Insert zero-width/tag characters inside a word. Humans see the lure; some scanners see fragments.
Why it mattered
If your phish rules are string-match on English, Unicode is a free bypass. Layered mail defense is why Microsoft says volume did not equal inbox success.
Who / what was affected
Microsoft telemetry, not a named victim sector. OT not applicable.
Technical context
Normalize Unicode before tokenizing. Hunt tag characters (U+E0001–U+E007F class) in subjects/bodies. Do not rely on one Unicode YARA.
Exploitation / threat status at the time
CONFIRMED Microsoft volume and dates.
ASSESSED copycat of AI-research technique, not a new APT.
What defenders should have done
- Unicode normalization in mail pipelines.
- Do not retire the signature after 15 May — the campaign continued without it.
- Treat "funding" fragments as the same lure.
RWP assessment
Confidence: High on telemetry. This is filter-evasion fashion, not a 0-day.
Defensive actions
- Normalize then detect.
- Keep layered Defender/equivalent policies.
- Brief IR that "clean-looking English" can still be smuggled.