$ techbeacon▋
Phishing

Hackers Exploit AI Prompt‑Injection to Slip Phishing Content Past Email Defenses

Hackers Exploit AI Prompt‑Injection to Slip Phishing Content Past Email Defenses

Security researchers have uncovered a new wave of email‑based phishing attacks that hide malicious content using a technique called ASCII smuggling, a form of AI prompt‑injection that inserts invisible Unicode characters into messages. The method allows threat actors to embed financial fraud lures in plain‑text emails while evading the detection mechanisms of most corporate email gateways.

According to observations from Microsoft’s threat intelligence team, the campaign has already been seen in more than 2.3 million email messages worldwide. By sprinkling zero‑width and other non‑printing characters throughout the body of the email, the attackers can alter how the text is rendered for a human reader without changing the string that security scanners analyze. The result is a phishing lure that appears benign to automated filters but becomes readable once the message is displayed in a standard email client.

The technique builds on earlier prompt‑injection research that demonstrated how AI models can be tricked into generating unintended output. In this case, the malicious actors have adapted the concept for a non‑AI delivery channel, leveraging the fact that many modern email security products rely on string matching and pattern recognition that do not normalize Unicode control characters. As a consequence, the hidden phishing links or credential‑harvesting forms can slip past filters that would otherwise block known malicious URLs.

Financial phishing remains a lucrative target for cybercriminals, and the use of ASCII smuggling raises the stakes for defenders. Traditional defenses such as URL reputation checks, attachment sandboxing, and domain‑based message authentication (DMARC, DKIM, SPF) are less effective when the malicious payload is concealed in the email body itself. Experts recommend that organizations supplement existing tools with Unicode normalization steps, heuristic analysis of character entropy, and user education that highlights the risk of unexpected or oddly formatted messages.

Microsoft has not disclosed specific details about the groups behind the operation, but the scale of the activity suggests a coordinated effort, possibly linked to financially motivated cybercrime networks. The company plans to roll out updates to its Defender for Office 365 service that incorporate detection rules for invisible Unicode sequences. As the technique gains visibility, security vendors are expected to follow suit, and analysts warn that attackers may evolve the approach further, embedding code in other communication channels such as chat or document files. Continuous monitoring and rapid adaptation of email security policies will be essential to mitigate this emerging threat vector.

Source: GBHackers
Threat Desk — Threat desk.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related