The phish in your quarantine report looks clean because your stack never read the real words.

Microsoft researchers just documented ASCII smuggling crossing from AI prompt injection into phishing. Invisible Unicode characters, the same ones used to hide instructions from models, now obfuscate words before email filters parse them. If your cybersecurity scoring still tokenizes the visible string, you are grading a decoy. Threat-protection rules fire on phrases like wire transfer and password reset. Those strings can sit in tag characters and zero-width code points your gateway treats as nothing. The version a person reads looks like a Tuesday.

That is a content-inspection failure sitting in production right now.

Hidden characters already beat the gateway

ASCII smuggling works because most mail pipelines normalize poorly. They strip HTML, decode MIME, then match keywords, URLs, and reputation. They do not always canonicalize Unicode. They do not always strip format characters in the Cf category. They rarely alert when a message contains a second, invisible layer of text.

Diagram-style graphic on adversarial AI techniques used to hide instructions from automated parsers
The same Unicode hiding tricks that grew up around prompt injection are now aimed at your mail filters.

Attackers insert zero-width joiners, tag characters, and bidirectional overrides between letters. A filter sees fragments. A mailbox client may render a clean sentence. Some clients hide the smuggled run entirely. Some show garbled junk a busy person ignores. Either way, the match your threat detection expected never happens.

Homoglyphs do the rest. Latin e and Cyrillic е look identical on the glass. URL filters and DLP that key off ASCII bytes miss the swap. You already know this from domain lookalikes. It now lives inside the body, the subject, and the display name.

The clean mail is the one built for the scanner.

You cannot usefully stop this with a firewall allow-list. The session is permitted. The sender may be a mailbox you already trust. Brute-force noise on the VPN will still fill the queue while this message scores as routine business. If your SOC measures health by lockouts and blocked logins, this class of mail never shows up in the dashboard that gets read.

The merger pitch is the lure

Dark Reading’s reporting on the Phantom Deal campaign is the business face of the same gap. Operators study target companies in extreme detail. They aim at midlevel staff who can initiate wires. The ask is a large financial transfer wrapped in merger-and-acquisition language. NDAs. Deal rooms. Counsel. Tight timelines. That mail needs to look like work.

Person reviewing a non-disclosure agreement document on a desk
Phantom Deal operators wrap large transfers in NDAs, counsel, and deal-room urgency aimed at midlevel staff.

Give those operators a way to hide the words your filters hunt, and the visible layer can stay boring. A subject line about a confidential close can render as harmless collaboration. The tokens your DLP was bought to catch can live in a stream nobody rendered. Unit 42 separately described attackers targeting Latin American organizations with AI tooling for data exfiltration. Their OpSec was sloppy enough that defenders could disrupt them. Tradecraft is uneven this week. The lures are getting more specific. The channel still looks like collaboration.

Treat high-value business processes as unauthenticated until a second channel confirms them. Finance already knows the vendor-bank-change scam. M&A theater is the same play with better research.

Cybersecurity must parse the raw bytes

If you run cyber security for a mail environment, stop scoring the rendered preview. Score the bytes.

Immediate and ongoing work, in that order:

  • Normalize inbound text to NFKC, strip or flag Unicode format (Cf) and tag characters, and resolve bidirectional overrides before any keyword, DLP, or URL check runs.
  • Alert on messages with zero-width characters, mixed-script tokens in Latin-looking words, or a large gap between visible length and raw length.
  • Require dual control and an out-of-band call on any wire change, vendor-bank update, or M&A-related transfer, using a number you already have.
  • Preserve original .eml files in incident response and dump code points before you close a ticket that says the user clicked a clean message. Keep that hunt in the standing playbook.

Ongoing security hardening is pipeline order. Decode, canonicalize, then detect. Defense in depth here means finance DLP and payment dual-control still fire when the gateway is wrong. Train the SOC to treat Unicode anomalies as a detection class, the same way you treat impossible travel. Watch public deal chatter, exec moves, and org charts. That recon is how Phantom Deal reads like an insider. Pull a week of mail that mentioned legal, treasury, or NDA and re-parse it with format characters stripped. You want the delta between what the gateway logged and what a human saw.

Do this even if your vendor swears the gateway is AI-powered. Models are how this trick was popularized. They are a weak last parser.

The operators will keep writing two emails in one file. Read both.

Sources

Take Control of Your Server Security

Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.

Secure. Automated. Lightweight.

Stay up to date with the latest news, releases and more.

Take Control of Your Server Security

Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.

Secure. Automated. Lightweight.