Zero Day Room
Live
Threats

Microsoft Warns of High-Volume Phishing Campaign Using

Microsoft has alerted of a phishing campaign using invisible Unicode tag characters to split financial keywords and evade email filters, with peak volumes

Microsoft has alerted of a phishing campaign using invisible Unicode tag characters to split financial keywords and evade...

Microsoft is warning of a high-volume phishing campaign that uses invisible Unicode tag characters to bypass email security filters. The campaign, which began in early February 2026, involves splitting financial lure words like 'funding' with non-rendering characters from the Unicode Tags block (U+E0000 to U+E007F) to avoid detection by keyword-based filters. According to Microsoft Security Research, the tactic makes malicious text appear normal to users while disrupting automated parsing systems that rely on exact string matches. The campaign peaked on February 26, 2026, with weekday volumes estimated between 1 and 2.37 million messages. Activity followed a weekly pattern, dropping sharply on weekends and resuming each Monday, before declining after May 15, 2026. The phishing emails were distributed via the ActiveCampaign marketing platform, which threat actors used to send AI-generated emails targeting Small Business Administration loan applicants. Fortra Intelligence and Research Experts first disclosed details of the broader campaign in September 2025, noting its focus on harvesting business and financial data for future spear-phishing attacks. Fortra highlighted the campaign’s sophistication in generating tailored phishing sites at scale using ActiveCampaign’s automation tools. Microsoft explained that inserting invisible characters-such as U+E0020-inside words like 'funding' results in obfuscated strings like 'fun⟨U+E0020⟩ding', which appear normal to recipients but break literal keyword matching in security filters. While the use of invisible characters in phishing is not new, Microsoft noted the novelty lies in the specific use of the Unicode Tags block and the campaign’s massive scale. The emails originated from hundreds of disposable finance-themed domains, including guardiangrowthfunding[.]com, digitalcapitalboost[.]com, and thebusinessloanexpress[.]com. All outbound links in the messages were routed through ActiveCampaign’s click-tracking domains, acemlnd[.]com and activehosted[.]com. ActiveCampaign stated it has tested its content moderation with such messages and treats heavy use of invisible Unicode as a suspicious signal, though obfuscated emails currently receive the same verdict as their unobfuscated versions. Microsoft warned that abuse of reputable platforms like ActiveCampaign can complicate reputation-based filtering, as malicious activity may resemble legitimate marketing traffic. The campaign relied on lures mimicking business loans, lines of credit, and advance funding to harvest credentials and financial information. No patch or direct control was mentioned in the source as stopping the campaign, though detection evasion via Unicode obfuscation remains the central technique described.

Related coverage

More from Threats