{"id":836497,"date":"2026-09-04T18:52:11","date_gmt":"2026-09-04T18:52:11","guid":{"rendered":"https:\/\/www.newsbeep.com\/us\/836497\/"},"modified":"2026-09-04T18:52:11","modified_gmt":"2026-09-04T18:52:11","slug":"once-popular-for-attacking-ai-ascii-smuggling-is-embraced-by-spammers","status":"publish","type":"post","link":"https:\/\/www.newsbeep.com\/us\/836497\/","title":{"rendered":"Once popular for attacking AI, ASCII smuggling is embraced by spammers"},"content":{"rendered":"<p>A clever technique used to hide malicious prompts in attacks on AI agents has been adopted by spammers to evade filters on email platforms that are designed to flag unwanted messages used in mass campaigns.<\/p>\n<p>The technique is broadly known as ASCII smuggling. It gained attention two years ago as a means of making a class of AI attack known as <a href=\"https:\/\/arstechnica.com\/security\/2026\/07\/hackers-can-use-9-of-the-most-popular-ai-tools-to-assemble-massive-botnets\/\" rel=\"nofollow noopener\" target=\"_blank\">prompt injections<\/a> more stealthy. Malicious instructions embedded in emails or other untrusted content to be processed by an LLM aren\u2019t written in ordinary text. Instead, they\u2019re rendered by a special range of <a href=\"https:\/\/en.wikipedia.org\/wiki\/Unicode\" rel=\"nofollow noopener\" target=\"_blank\">Unicode<\/a> tags. For example, the tag point U+E0041 mirrors \u201cA,\u201d and U+E0061 mirrors \u201ca.\u201d<\/p>\n<p>No longer just for obscuring prompt injections<\/p>\n<p>The block of 128 tags mimics a portion of the <a href=\"https:\/\/en.wikipedia.org\/wiki\/ASCII\" rel=\"nofollow noopener\" target=\"_blank\">American Standard Code for Information Interchange<\/a> almost perfectly, with one major difference: the characters they encode are readable by computers but, by design, are almost completely invisible to humans. By expressing the malicious prompts in these tags, LLMs detect the instructions, but people reading the email never see them. There\u2019s much more about ASCII smuggling <a href=\"https:\/\/arstechnica.com\/security\/2024\/10\/ai-chatbots-can-read-and-write-invisible-text-creating-an-ideal-covert-channel\/\" rel=\"nofollow noopener\" target=\"_blank\">here<\/a>.<\/p>\n<p>Earlier this year, Microsoft started seeing a massive increase in spam messages that used the technique. Beginning on one day in early February, the number of ASCII smuggling signatures detected by Microsoft Defender for Office spiked from roughly 21,000 per day to more than 1.3 million. Within four days, signature detections jumped to 2.5 million. The deluge persisted for months and then fell off sharply in mid-May.<\/p>\n<p>\u201cBecause tag characters are invisible to humans but exist at the text-processing level, the same property that makes them useful for smuggling instructions into a model also makes them useful for obfuscating keywords before a detector evaluates them,\u201d Microsoft <a href=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/2026\/09\/03\/ascii-smuggling-crosses-over-from-ai-prompt-injection-to-phishing-evasion\/\" rel=\"nofollow noopener\" target=\"_blank\">explained Thursday<\/a>. \u201cThe intent is inverted, but the mechanism is similar, and a user\u2019s suspicions are not raised.\u201d<\/p>\n","protected":false},"excerpt":{"rendered":"A clever technique used to hide malicious prompts in attacks on AI agents has been adopted by spammers&hellip;\n","protected":false},"author":2,"featured_media":836498,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[45],"tags":[182,181,507,74],"class_list":["post-836497","post","type-post","status-publish","format-standard","has-post-thumbnail","category-artificial-intelligence","tag-ai","tag-artificial-intelligence","tag-artificialintelligence","tag-technology"],"_links":{"self":[{"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/posts\/836497","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/comments?post=836497"}],"version-history":[{"count":0,"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/posts\/836497\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/media\/836498"}],"wp:attachment":[{"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/media?parent=836497"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/categories?post=836497"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/tags?post=836497"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}