Spammers adopt ASCII smuggling to bypass email spam filters
A method originally used to conceal prompt-injection attacks on AI models, known as ASCII smuggling, is now being leveraged by spammers to hide malicious content from email security systems.
ASCII smuggling, a tactic that encodes text using a special range of Unicode tags invisible to human readers, was initially highlighted as a way to make prompt-injection attacks on large language models harder to spot. The tags replicate the appearance of standard ASCII characters while remaining detectable only at the text-processing level. Spammers have repurposed this approach to conceal malicious instructions in email messages, effectively bypassing filters that rely on keyword detection.
Microsoft Defender for Office observed a dramatic increase in signatures matching ASCII smuggling, with daily detections climbing from roughly 21,000 to more than 1.3 million on a single day in early February, and reaching 2.5 million within four days. The influx persisted for months before dropping sharply around mid-May. According to Microsoft, the invisible nature of the tags makes them useful both for feeding hidden prompts to AI models and for obscuring spam content from automated defenses.
Why it matters
The reuse of AI-evasion tricks by spammers threatens the effectiveness of email security filters.
In this story
