English

SecurityMicrosoft

ASCII smuggling attack method exploited to bypass spam email filters

This article is a translation. Read the Japanese original

Microsoft has announced a rapid increase in spam emails utilizing a technique known as ASCII smuggling.

This method involves embedding characters within text that are invisible to humans but readable by computers, using specific Unicode tags.

Originally, this technology was used in attacks against AI to hide malicious instructions and make them recognizable to LLMs.

According to Microsoft, since around 2026-02, the number of ASCII smuggling signatures detected by Microsoft Defender for Office has surged from approximately 20,000 per day to over 1.3 million per day.

Spammers are exploiting this characteristic by inserting invisible characters into the middle of keywords targeted by detection systems, such as "funding" and "credit."

As a result, the tokenizer on the email filter side fails to recognize the words correctly, making it possible to evade detection.

Meanwhile, because the characters appear normally on the recipient's screen, users do not find anything suspicious.

Microsoft has released guidelines for developers to address these types of attacks.


Source: Once popular for attacking AI, ASCII smuggling is embraced by spammers (Ars Technica AI, 2026-09-05)