Phishing Campaign Uses Invisible Unicode to Evade Email Filters
Executive Summary
Microsoft warns of a high‑volume phishing campaign that inserts invisible Unicode tag characters into email text to split financial lure words (e.g., 'funding'), thereby bypassing spam filters. The attackers exploit the characters’ ability to hide content from filtering engines while remaining visible to AI models. The campaign targets users with financial‑related phishing emails.
Intelligence Metadata - Source Publisher: The Hacker News - Published Date: 2026-09-04T15:57:15+00:00 - Category: threat-intel
Original Description: Microsoft is alerting of a "high-volume phishing campaign" that's using invisible Unicode tag characters to bypass email filters. "Instead of using these characters to hide instructions from people while exposing them to AI models, the attacker used them to split financial lure words such as 'funding' to prevent email filters from parsing them," the Microsoft Security Research team said. The
"Through pride we are ever deceiving ourselves. But deep down below the surface of the average conscience a still, small voice says to us, Something is out of tune."
— Carl Jung