Hackers are concealing phishing lures in emails by using “invisible” Unicode characters, Microsoft warns, making the bait harder to detect. The technique can involve characters that do not visibly change the displayed text but can alter the underlying content of the message.
According to reporting from TechRadar and Bleeping Computer, the approach represents an adaptation of “ASCII smuggling” or similar character-manipulation methods previously discussed in other contexts, including prompt injection. Attackers insert these concealed Unicode characters into the email content to help lure recipients while evading email security filters that rely on text matching and inspection.
Both outlets describe the broader goal as bypassing automated defenses rather than changing the core phishing theme. While the sources agree on the general method and the use of invisible characters to reduce detection, they differ mainly in how they frame the technique’s lineage (e.g., linking it to prompt injection versus emphasizing ASCII smuggling).