Microsoft Exposes Sneaky Unicode Trick Hiding In Millions Of Emails

Official Microsoft Insights graphic.
Microsoft Insights graphic. Image: Microsoft

Keyword smuggling, which is the practice of obfuscating spam keywords to bypass detection filters, has been common practice for quite some time. Microsoft is warning that this traditional tactic has been enhanced by a new-school method of ASCII smuggling, which was originally used for AI prompt injection attacks. Now, ASCII smuggling is also being used to perform keyword smuggling by stuffing an empty ASCII tag into words known to flag detection systems.

This ASCII smuggling campaign seemed to start around February 2nd, when between 5 and 20 thousand spam emails using the technique were detected by Microsoft. The volume rapidly jumped up to 1.32 million on February 8th, increased to a peak of 2.37 million on February 11th, and maintained high levels until February 14th. There, it briefly peters off as low as 14 thousand before shooting back up to 1.5 million. Following that activity, a continuous wave of on-and-off weekday peaks proceeded through March into mid-June.

Timeline of ASCII keyword smuggling scam.
Timeline of ASCII keyword smuggling scam. Image: Microsoft

Per Microsoft's documentation, this pattern marks the behavior of a coordinated attacker buying computational attack power. That's why the attacks are sent out in surges, at least by Microsoft's estimation. But if enough of these emails bypass filters while also containing dangerous enough malware or phishing links, they pose a significant threat.

Fortunately, ASCII smuggling is just a newer variation of the classic keyword smuggling tactic. This means that existing security software can be updated to filter it out relatively quickly. Adding common ASCII filler tags to your filters would be a good place to start.

As both Microsoft and we will warn you, it's always important to be vigilant and maintain updated protection against spam and phishing emails. Informing your employees, coworkers, customers, or family members about cybersecurity risks can help prevent them from making bad decisions when they see an official-looking email that is actually a scam.
Chris Harper

Chris Harper

Christopher Harper is a tech writer with over a decade of experience writing how-tos and news. Off work, he stays sharp with gym time & stylish action games.