Microsoft Flags Unicode Character Trick Used to Evade Phishing Detection at Scale
Microsoft Security Research disclosed on September 3, 2026, that attackers are embedding invisible Unicode Tags block characters — such as U+E0020 — inside financial terms like 'funding' and 'loan' in phishing emails to bypass string-matching and regex-based detection systems. The campaign, which targeted recipients with business funding and credit-line lures, reached sending volumes of up to 2.37 million messages on peak weekdays. Emails were delivered through infrastructure linked to the legitimate email marketing platform ActiveCampaign, with links routed via its click-tracking domain, lending the messages an air of authenticity. Microsoft identified a cluster of 148 finance-related sender domains on February 9, 2026, and reported that Defender for Office 365 blocked over 99% of the messages through alternative detection layers. The company recommends that security pipelines normalize or strip invisible Unicode characters from email content before applying detection logic to prevent evasion.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in