ARTIFICE DAILY AI + CYBER SECURITY BRIEFING

Cybersecurity

Microsoft flags phishing campaign using invisible Unicode

Microsoft said a phishing operation used invisible Unicode tag characters to split lure words, evade email filters and send millions of messages a day before activity dropped in May 2026.

The Hacker News

Microsoft said the campaign inserted invisible Unicode tag characters into ordinary-looking lure words so that recipients still saw readable text while filters were less likely to recognise the terms. The company said the method let attackers evade keyword and signature checks.

According to Microsoft, the activity entered a high-volume period for about three months before dropping sharply after 15 May 2026. It said weekday traffic ranged from 1 million to 2.37 million messages, with a peak on 26 February and little activity at weekends.

Microsoft said the operation was connected to a broader phishing campaign that used ActiveCampaign to distribute AI-generated emails aimed at Small Business Administration loan applicants. Fortra's FIRE team had disclosed that related campaign in September 2025 and said it was collecting business and financial details for later spear-phishing.

ActiveCampaign said it had tested its content-moderation systems against messages containing invisible Unicode characters and that such emails received the same moderation outcome as unobfuscated ones. It also said heavy use of the technique was treated as a suspicious signal, while Microsoft said legitimate marketing infrastructure could make the traffic harder to filter by reputation.

Named in this story

Companies

Microsoft
alerted to the phishing campaign and published the findings
ActiveCampaign
its platform carried the emails and it responded on moderation

Organisations

Microsoft Security Research team
explained how the invisible characters were used
Fortra Intelligence and Research Experts (FIRE) team
disclosed the related campaign in September 2025

Governments and agencies

Small Business Administration
its loan applicants were among the earlier targets

How the source tells it

The piece reads as a technical security alert, with repeated emphasis on novelty, scale and urgency.

  • novelty It explicitly marked the character choice and the campaign scale as the new element.
  • urgency The lead framed the story as a warning and stressed an active phishing operation.
  • scale emphasis It repeated million-message estimates, a daily peak and weekday volume figures.