Microsoft identified a high-volume finance-themed phishing campaign that embedded invisible Unicode Tag characters—principally U+E0020 TAG SPACE—within lure terms such as “funding.” The technique, a repurposing of ASCII smuggling research associated with AI prompt-injection evasion, leaves text readable to recipients while breaking literal keyword matches and potentially disrupting ML/NLP email-analysis pipelines. Microsoft reported that the activity began abruptly on February 9, peaked above 2.3 million messages per day, operated largely on weekdays, and remained high-volume until declining after May 15.
The operators rotated approximately 150 finance-themed sender domains and used the legitimate ActiveCampaign marketing platform for mail delivery and click tracking. Organizations should normalize or remove Unicode Tags-block characters (U+E0000–U+E007F) and other invisible Unicode characters before applying signatures, regular expressions, or AI-based content inspection; unexpected use of these characters should be treated as a phishing anomaly signal.

Get the infrastructure and lures behind it.
9 events from the most recent confirmed update back to the earliest known activity.
Lower-volume residual activity using the Unicode-tag-character technique remained observable through mid-June.
The campaign's high-volume use of Unicode tag-character insertion dropped sharply after roughly three months of activity. The broader SBA-themed, ActiveCampaign-delivered phishing campaign continued after this technique declined.
Microsoft reported a further daily peak for the Unicode-tag phishing activity during its high-volume phase.
Microsoft measured more than 2.3 million campaign messages during a daily peak in the high-volume Unicode-tag-character phase.
Microsoft telemetry rose to more than 1.3 million signature hits as a finance-themed campaign inserted invisible U+E0020 TAG SPACE characters into lure terms to evade content detection. The campaign operated on a weekday-only cadence and used finance-themed sender domains with ActiveCampaign delivery infrastructure.
Microsoft's ASCII-smuggling hunting signature recorded roughly 21,000 hits associated with the finance-themed phishing activity.
Microsoft identified 148 finance-themed domains responsible for about 96% of detected ASCII-smuggling messages and said Defender detected more than 99% of the messages using non-content indicators. It recommended stripping invisible Unicode characters before content inspection and before submitting email text to AI assistants.
ActiveCampaign said its testing found that messages containing invisible Unicode characters receive the same moderation verdicts as unobfuscated equivalents. It also said heavy use of invisible Unicode characters is treated as a suspicious moderation signal.
Fortra documented an SBA-lending impersonation campaign using ActiveCampaign infrastructure, personalized lures, and AI-generated phishing-site variants. The sites collected detailed business and financial information and then prompted victims to call a phone number, potentially enabling follow-on vishing.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 58 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
16 references tracked. Mallory keeps watching after this page renders.
xakep.ru
Open sourceitpro.com
Open sourcemkd-cirt.mk
Open sourceinfosec.pub
Open sourcecyberveille.ch
Open sourcemalware.news
Open sourcemicrosoft.com
Open sourcefortra.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.