Friday, September 4, 2026
Tech Beat
Sep 4, 2026, 5:18 PMCybersecurity

ASCII Smuggling Spam Surges to 2.5 Million Daily Microsoft Defender Detections

Microsoft saw ASCII smuggling spam signatures surge from 21,000 to 2.5 million daily as invisible Unicode tags fooled modern email filters and AI models.

Listen to this briefingAudio briefing

Summary

ASCII smuggling, previously used to conceal prompt injections from humans while exposing them to large language models, is now helping spammers evade email filters. Its 128 Unicode tags imitate part of ASCII but remain nearly invisible, with U+E0041 representing “A” and U+E0061 representing “a.” Attackers insert tags into terms such as “funding,” dollar amounts, “credit” and “term,” disrupting literal, regex, machine learning and natural language processing checks while recipients see normal wording.

Microsoft Defender for Office detections jumped on one day in early February 2026 from about 21,000 daily signatures to more than 1.3 million, then reached 2.5 million within four days. The surge persisted for months before dropping sharply in mid-May; Microsoft measured daily finance-themed sender-domain hits from February 9 through June 18. Spammers have used zero-width and non-breaking spaces similarly for decades, but Unicode tags likely exploited filters not programmed for them and, more importantly, disrupted tokenization used by ML and NLP classifiers. An inserted U+E0020 can split “funding” into “fun,” an unexpected tag and “ding,” produce unknown tokens, or disappear during normalization. Visual OCR can recover what humans see, and Microsoft issued developers defensive guidance Thursday.

Positives

  • Microsoft Defender for Office identified the campaign as detections accelerated from roughly 21,000 to millions per day.
  • Microsoft issued developers guidance Thursday for making spam filters account for hidden Unicode tags.
  • Normalization performed before classification can remove an inserted U+E0020 and restore the intended word.
  • OCR extraction can evaluate the message’s visible appearance instead of relying only on manipulated underlying text.

Risks & concerns

  • Daily ASCII smuggling signatures exceeded 1.3 million from roughly 21,000, then reached 2.5 million within four days.
  • Invisible Unicode tags can conceal dollar amounts and terms including “funding,” “credit” and “term” from email filters.
  • Inserted tags can break familiar words into rare or unknown tokens, weakening machine learning and natural language processing classifiers.
  • The campaign persisted for months before falling sharply in mid-May, showing the technique operated at sustained scale.
Primary sourceAI - Ars Technicahttps://arstechnica.com/security/2026/09/once-popular-for-attacking-ai-ascii-smuggling-is-embraced-by-spammers/
Read full article
Editorial note: Tech Beat summarizes and analyzes third-party reporting. The source link is the authoritative article. This page does not reproduce the full source text.

More From The Wire

CybersecuritySep 4

US Military Disables Ad Tracking to Protect Troops From Location Attacks

CybersecuritySep 3

OVERCAST PANDA USB Attack Exposes Executive Laptop Boot Gap

CybersecuritySep 3

OpenAI Commits $1 Billion to Daybreak Cyber AI Initiative