Home · Technology · Sep 6 archive
ASCII Smuggling: Spammers Adopt Invisible Unicode to Evade Filters
Confirmed
In Short: A technique once used to attack AI models is now being embraced by spammers to evade email filters, leading to a surge in phishing campaigns.
A once-overlooked block of unicode that’s invisible to humans is gaining ever wider use, particularly among spammers looking to evade filters on email platforms, according to reports from Ars Technica and The Indian Express.
On February 1, the number of ASCII smuggling signatures detected by Microsoft Defender for Office spiked from roughly 21,000 per day to more than 1.3 million, indicating a significant increase in its use.
Because tag characters are invisible to humans but exist at the text-processing level, the same property that makes them useful for smuggling instructions into a model also makes them useful for obfuscating keywords before a detector evaluates them, explained Microsoft.
Spammers are embedding Unicode in an attempt to evade filters that search for text, such as dollar amounts and the words 'credit' and 'term' that are commonly found in their mass emails, according to The Indian Express.
Since the start of the year, there has been a surge in the number of spam messages delivered to email inboxes with the help of ASCII smuggling, according to Microsoft researchers, who observed a high-volume phishing campaign involving ASCII smuggling.
What's confirmed
- The technique is broadly known as ASCII smuggling.
What's still developing
- A clever technique used to hide malicious prompts in attacks on AI agents has been adopted by spammers to evade filters on email platforms that are designed to flag unwanted messages used in mass campaigns.
- However, spammers continue to find new ways to bypass these defences using sophisticated techniques.
