ASCII smuggling crosses over from AI prompt injection to phishing evasion
Microsoft researchers identified a high-volume phishing campaign utilizing invisible Unicode tag characters (U+E0000 to U+E007F), a technique originally associated with AI prompt injection research known as ASCII Smuggling. The attackers inserted these invisible characters into financial keywords like 'funding' to evade email filters rather than hiding instructions from users. The campaign began February 9, 2026, generating millions of daily messages for approximately three months with a distinctive weekday-only pattern. Finance-themed disposable domains were used to send business loan and credit-line phishing through a legitimate email marketing platform. The technique, while designed for AI security contexts, proved effective at bypassing traditional keyword-based detection by splitting words with invisible characters that appear normal to recipients but break signature matches and alter ML tokenization.
Indicators of Compromise
- domain: ourbusinessloans.com
- domain: advancefundingboost.com
- domain: catalystboostfunding.com
- domain: catalystcapitalharbor.com
- domain: digitalcapitalboost.com
- domain: digitalrushcapital.com
- domain: directcapitalboost.com
- domain: directcapitalpulse.com
- domain: elevatecapitalrush.com
- domain: emsd4.com
- domain: fundingexpresscapital.com
- domain: guardiancapitalway.com
- domain: guardiangrowthfunding.com
- domain: guardianloccapital.com
- domain: guardianlocchoice.com
- domain: harboradvancefunding.com
- domain: onlinedirectfinance.com
- domain: rocketboostfunding.com
- domain: thebusinessloanexpress.com
- domain: unitedfundingwave.com
- domain: yourlocfunding.com
- domain: s9.acems10.com
ASCII smuggling crosses over from AI prompt injection to phishing evasion
Description
Microsoft researchers identified a high-volume phishing campaign utilizing invisible Unicode tag characters (U+E0000 to U+E007F), a technique originally associated with AI prompt injection research known as ASCII Smuggling. The attackers inserted these invisible characters into financial keywords like 'funding' to evade email filters rather than hiding instructions from users. The campaign began February 9, 2026, generating millions of daily messages for approximately three months with a distinctive weekday-only pattern. Finance-themed disposable domains were used to send business loan and credit-line phishing through a legitimate email marketing platform. The technique, while designed for AI security contexts, proved effective at bypassing traditional keyword-based detection by splitting words with invisible characters that appear normal to recipients but break signature matches and alter ML tokenization.
Technical Details
- Author
- AlienVault
- Tlp
- white
- References
- ["https://www.microsoft.com/en-us/security/blog/2026/09/03/ascii-smuggling-crosses-over-from-ai-prompt-injection-to-phishing-evasion/"]
- Adversary
- null
- Pulse Id
- 6a99b03218e13e137c1e5d0a
- Threat Score
- null
Indicators of Compromise
Domain
| Value | Description | Copy |
|---|---|---|
domainourbusinessloans.com | — | |
domainadvancefundingboost.com | — | |
domaincatalystboostfunding.com | — | |
domaincatalystcapitalharbor.com | — | |
domaindigitalcapitalboost.com | — | |
domaindigitalrushcapital.com | — | |
domaindirectcapitalboost.com | — | |
domaindirectcapitalpulse.com | — | |
domainelevatecapitalrush.com | — | |
domainemsd4.com | — | |
domainfundingexpresscapital.com | — | |
domainguardiancapitalway.com | — | |
domainguardiangrowthfunding.com | — | |
domainguardianloccapital.com | — | |
domainguardianlocchoice.com | — | |
domainharboradvancefunding.com | — | |
domainonlinedirectfinance.com | — | |
domainrocketboostfunding.com | — | |
domainthebusinessloanexpress.com | — | |
domainunitedfundingwave.com | — | |
domainyourlocfunding.com | — | |
domains9.acems10.com | — |
Threat ID: 6a9ab102acd9273b498670f8
Added to database: 09/04/2026, 11:52:34 UTC
Last updated: 09/04/2026, 16:13:23 UTC
Views: 9
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.