News September 7, 2026
Short Link:

The ASCII smuggling technique, once used to target AI systems, has now evolved into a tool for spammers. This method allows them to evade email filters, and in some cases, the secret use of Unicode has led to a significant spike in spam messages.
The ASCII smuggling technique, originally employed in attacks on artificial intelligence systems, is now being utilized by spammers to circumvent email filters. This method enables harmful content to be formatted in a way that is invisible to humans but recognizable by machines.
Microsoft researchers have reported a dramatic rise in the use of this technique since the beginning of the year. In early February, the number of identified ASCII smuggling signatures surged to 1.3 million per day, increasing to 2.5 million within just four days. This upward trend persisted for several months before experiencing a sudden decline in mid-May.
Spammers are using hidden Unicode to bypass keywords typically flagged by spam filters, including terms like “credit” and “term.” For instance, by inserting invisible characters in the word “funding”, filters only detect the visible parts, disregarding the hidden characters.
This technique also employs zero-width spaces and non-breaking spaces similarly. Spammers are exploiting these vulnerabilities in filters, as some are still unable to recognize this particular type of Unicode. The main challenge lies in the ability of filtering systems to detect these attacks without having to visually see the entire text.
On Thursday, Microsoft provided guidelines for developers to enhance their filters against ASCII smuggling. These changes could significantly impact the future of spam detection and present new challenges for content moderation online.