Invisible Unicode Tag Characters Used to Evade Phishing Detection in Financial Scam Campaign — Threadlinqs Intelligence
As of 2026-09-04, Invisible Unicode Tag Characters Used to Evade Phishing Detection in Financial Scam Campaign is a high-severity threat intel threat, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 19 indicators of compromise.
Threat ID: TL-2026-2331 · Severity: HIGH · Status: ACTIVE · Category: THREAT_INTEL
A high-volume, finance-themed phishing campaign inserted invisible Unicode Tag-block characters (U+E0000-U+E007F, including U+E0020 TAG SPACE) inside keywords such as "funding" and "loan" to defeat
In February 2026, Microsoft's hunting signature for ASCII-smuggling activity - Unicode text carrying invisible characters from the largely deprecated Unicode Tags block (U+E0000-U+E007F) - jumped from roughly 21,000 hits on February 8 to over 1.3 million messages within 24 hours on February 9, and continued to a sustained daily volume exceeding 2.3 million messages (peaking around February 11, with the single highest weekday volume of ~2.37 million on February 26). The elevated activity persisted for approximately three months with a distinctive weekday-only cadence (sharp weekend drops, resuming Mondays), declining substantially - roughly an 80% reduction from the initial peak by late March, and dropping off further after May 15, 2026.
The technique, popularized as "ASCII smuggling" in AI prompt-injection research (invisible Unicode Tag characters used to hide instructions from human reviewers while still being parsed by LLMs; MITRE ATLAS classifies this technique class as AML.T0068, LLM Prompt Obfuscation, and the same character range has separately been used to exfiltrate data from Microsoft Copilot), was repurposed here against traditional email security rather than against an AI system. Operators spliced the invisible TAG SPACE character (U+E0020) and other Tag-block code points into the middle of high-signal financial keywords - for example rendering "funding" while the underlying text carried "fun<U+E0020>ding" - so that literal keyword, signature, and regular-expression checks (and potentially token-based NLP/ML classifiers) failed to recognize the fragmented word, even though the message displayed normally to the recipient. A known benign source of the same code-point range - regional flag emoji (e.g., England/Scotland/Wales), which are built from Unicode Tag sequences - was flagged by Microsoft as a false-positive risk for any blanket tag-block filtering rule.
The campaign used approximately 148 disposable, finance-themed sender domains algorithmically built from a rotating vocabulary of roughly 28 business-loan/funding word-tokens (advance, boost, business, capital, catalyst, choice, digital, direct, elevate, express, finance, funding, growth, guardian, harbor, loan, loans, loc, online, our, pulse, rocket, rush, the, united, wave, way, your), including guardiangrowthfunding[.]com, digitalcapitalboost[.]com, thebusinessloanexpress[.]com, harboradvancefunding[.]com, unitedfundingwave[.]com, catalystcapitalharbor[.]com, rocketboostfunding[.]com, yourlocfunding[.]com, advancefundingboost[.]com, guardiancapitalway[.]com, and directcapitalboost[.]com. Lures offered unsolicited business-loan, funding, and credit-line deals with credential/financial-data-harvesting funnel characteristics consistent with the Fortra-documented precursor campaign (which impersonated the U.S. Small Business Administration's pre-selected "new line of credit" programs, promised $4-10M in funding within 48 hours, and used ActiveCampaign's AI-powered marketing automation to mass-produce varied, AI-generated landing pages that harvested detailed business and financial information - assessed as likely intended to fuel future, more targeted spear-phishing).
Messages were relayed through the legitimate ActiveCampaign email-marketing platform: roughly 92% of observed volume originated from a single /24 block, 173.236.20.0/24, corresponding to ActiveCampaign's shared sending infrastructure, and ~98.5% of volume matched recognizable ActiveCampaign envelope patterns (~99.8% matched envelope or tracking-URL patterns). Click-through links used ActiveCampaign's own tracking domains (activehosted[.]com, acemlnd[.]com) in a hxxps://<account-id>.acemlnd[.]com/<tracking-token> URL structure, and envelope (P1) senders followed recognizable shared-pool patterns such as em-<digits>.<brand-domain>, acems<N>[.]com, and emsd<N>[.]com.
Microsoft reported that over 99% of the campaign's messages were ultimately caught by layered Defender for Office 365 protections th
Target sectors: general business email users, small and mid-size business owners, financial services brand impersonation
Timeline
- Fortra's FIRE team publishes documentation of an earlier, related ActiveCampaign-delivered phishing operation impersonating U.S. Small Business Administration (SBA) pre-selected loan programs, using AI-generated websites promising $4-10M in funding to harvest detailed business/financial data; Microsoft later connects the 2026 ASCII-smuggling wave to this precursor activity.
- Microsoft's ASCII-smuggling hunting signature registers a baseline ~21,000 hits, the last quiet day before the campaign's onset.
- Sharp onset: hits on the hunting signature jump to over 1.3 million messages within 24 hours, marking the start of the high-volume phase; sustained weekday-on/weekend-off cadence begins across roughly 148 rotating finance-themed sender domains relayed through ActiveCampaign.
- Microsoft observes an early peak day of roughly 2.3 million messages carrying invisible Unicode Tag-block characters in finance-themed lures.
- Campaign reaches its highest single-day weekday volume, approximately 2.37 million messages.
- Volume has fallen roughly 80% from the initial peak by late March, though the campaign continues at reduced, still-elevated weekday volumes.
- Campaign volume declines substantially after this date, ending the high-volume phase observed by Microsoft telemetry.
- Microsoft Security publishes "ASCII smuggling crosses over from AI prompt injection to phishing evasion," detailing the campaign, its infrastructure, its link to the Fortra-documented SBA-themed precursor, and detection/normalization guidance.
- Cyber Security News and other outlets report on Microsoft's findings; the Cyber Security News article is ingested as the hunt source for this threat record.
Detections & IOCs
As of 2026-09-05, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 19 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
THREAT_INTEL, HIGH, threat intelligence, cybersecurity, T1598.003, T1583.001, T1583.006, T1585.002, T1566.002, T1204.001, T1027, T1036.005, T1684.001, T1657