All NewsEducationTVBrokers
Equities & FundsCrypto & Digital AssetsAI & TechnologyBusiness & CorporateUS Politics & PolicyGeopolitics & Global RiskMacro, Rates & FXCommodities & EnergyEuropean Politics & MarketsAsia-PacificReal Estate & Property
All NewsHome
← Back to AI & Technology

Spammers adopt AI attack technique to evade email filters

Created at 4 Sep · 5:26 PM1 source↑ Market-relevant
IN SHORT

Spammers are now using ASCII smuggling, a technique previously used to attack AI models, to hide malicious content and keywords from email filters. This method embeds invisible Unicode characters that trick both human readers and machine learning classifiers.

Key Numbers

128number of unicode tags in the ASCII smuggling block
21,000daily ASCII smuggling signatures detected by Microsoft Defender before February
1.3 milliondaily ASCII smuggling signatures detected by Microsoft Defender after February 2
2.5 milliondaily ASCII smuggling signatures detected within four days of the spike

Who's Involved

Microsoft
observed a massive increase in spam messages using ASCII smuggling
Dan Goodin
Senior Security Editor at Ars Technica
Spammers adopt AI attack technique to evade email filters

↳ Why This Matters

The widespread adoption of ASCII smuggling by spammers highlights a persistent cat-and-mouse game between malicious actors and email security systems, forcing continuous adaptation of filtering technologies to protect users from unwanted and potentially harmful content.

Key facts

  • Spammers are using ASCII smuggling, a technique previously employed for AI attacks, to evade email filters.
  • This method utilizes invisible Unicode characters that are readable by machines but not by humans.
  • Microsoft Defender for Office saw a dramatic increase in ASCII smuggling signatures starting in February 2026.
  • The technique aims to bypass filters that scan for keywords commonly found in spam, such as financial terms.
  • Machine learning and natural language processing models used for spam classification can be tricked by this method.
  • A technique once used to make AI attacks more stealthy, known as ASCII smuggling, is now being adopted by spammers to bypass email filters. This method involves embedding invisible Unicode characters that are readable by computers but undetectable to human eyes. These characters mimic standard ASCII characters, allowing malicious instructions or keywords to be processed by AI systems or email filters without being seen by the recipient.

    Microsoft reported a significant surge in spam messages employing this technique, with daily detections of ASCII smuggling signatures jumping from approximately 21,000 to over 1.3 million in early February 2026. The deluge continued for months before declining in mid-May. Spammers leverage ASCII smuggling to obscure keywords commonly flagged by filters, such as financial terms, by inserting invisible characters within words. For instance, a filter might see "fun" and "ding" instead of "funding" if invisible characters are interspersed.

    While spammers have historically used methods like zero-width spaces to evade filters, the adoption of invisible Unicode tags is likely due to their effectiveness against newer machine learning and natural language processing-based spam detection systems. These systems often process text by splitting it into tokens or sub-word pieces, and the invisible characters can disrupt this process, causing the classifier to misinterpret or miss the intended keywords. Microsoft has since released guidance for developers to improve their filters' ability to detect this type of attack.

    Frequently asked questions

    ASCII smuggling is a technique that uses a special range of invisible Unicode tags to embed text that is readable by computers but undetectable to humans. It was initially used to hide malicious prompts in AI attacks.

    Spammers are embedding these invisible Unicode characters into their messages to evade filters that search for specific keywords associated with spam, such as financial terms. The characters can also disrupt machine learning models used for spam classification.

    Microsoft Defender for Office saw a dramatic increase in detected ASCII smuggling signatures, spiking from around 21,000 per day to over 1.3 million daily in early February 2026, indicating a significant challenge for existing spam filters.

    What Happens Next

    01Microsoft has provided guidance on programming filters to better account for ASCII smuggling.
    CME Headlines
    • Risk Management and Monitoring Notice: Multi-Factor Authentication Updates - September 12
      3 Sep · 5:00 AM

    How It Developed

    ASCII smuggling, a technique for hiding malicious prompts in AI attacks, is now being used by spammers.
    This method embeds invisible Unicode characters that are readable by computers but not humans.
    Microsoft observed a significant increase in spam messages using ASCII smuggling in February 2026.
    The number of detected ASCII smuggling signatures spiked from 21,000 to over 1.3 million daily.
    Spammers use the technique to obfuscate keywords like dollar amounts and 'credit' from spam filters.
    The invisible characters can disrupt keyword searches and fool machine learning models used in spam detection.
    Microsoft has provided guidance on programming filters to better detect ASCII smuggling in spam.

    Sources

    T1
    Once popular for attacking AI, ASCII smuggling is embraced by spammersvar abtest_2170523 = new ABTest(2170523, 'impression');Ars Technica

    Related Stories

    New algorithm mimics fruit fly's scent memory, avoids 'catastrophic forgetting'
    3 Sep · 6:26 PM
    Startup Abliteration.ai offers commercial service for AI models stripped of guardrails
    3 Sep · 6:46 PM
    OpenAI agents hijacked German wiki to share rule-breaking tactics, report says
    4 Sep · 10:06 AM
    OpenAI agents posted on German wiki without company knowledge
    4 Sep · 4:41 PM
    Valve orchestrated Left 4 Dead 2 trailer leak to bypass ESRB
    4 Sep · 4:51 PM