Spammers are using invisible Unicode tag characters to evade filters, adapting a method first known for concealing prompt injections. ASCII smuggling uses a block of 128 Unicode tag characters that are nearly invisible to people. The characters can still be processed by software and language models.

The technique first drew attention as a way to hide prompt-injection instructions. Microsoft observed daily Defender signatures rise from about 21,000 to more than 1.3 million at the start of a February surge. ASCII smuggling uses machine-readable but visually hidden Unicode tags to break words apart for automated filters while leaving them legible to people. Microsoft observed detections jump from roughly 21,000 a day to millions.

Within four days, detections reached about 2.5 million. The elevated activity persisted for months before falling sharply in mid-May. Spammers have long used zero-width and nonbreaking spaces to alter text matching.

Invisible tags can disrupt literal strings, regular expressions, tokenization and machine-learning classifiers. Microsoft published defensive guidance for normalizing or detecting the characters. Technical capability, institutional policy and reported observation are kept distinct in the account.

The evidence available for this dated edition has a defined boundary: Detection counts measure signatures seen by Microsoft systems and do not establish the number of people who received or acted on malicious messages. Further reporting is expected on adoption by additional spam campaigns and whether major mail systems normalize these unicode tags before classification.

The retained source record for “AI Attack Technique Migrates Into Mass Spam” consists of Ars Technica reporting linked below. It establishes these checked points for September 8: ASCII smuggling uses a block of 128 Unicode tag characters that are nearly invisible to people. The characters can still be processed by software and language models. The technique first drew attention as a way to hide prompt-injection instructions. Microsoft observed daily Defender signatures rise from about 21,000 to more than 1.3 million at the start of a February surge. Within four days, detections reached about 2.5 million. The elevated activity persisted for months before falling sharply in mid-May. The relevant background is: Spammers have long used zero-width and nonbreaking spaces to alter text matching. Invisible tags can disrupt literal strings, regular expressions, tokenization and machine-learning classifiers. Microsoft published defensive guidance for normalizing or detecting the characters. This synthesis does not extend beyond those cited facts and stated uncertainties.