A clever technique known as ASCII smuggling, initially used to hide malicious prompts in AI attacks, has been repurposed by spammers to bypass email filters designed to detect unwanted messages. This method gained prominence two years ago as a way to enhance the stealth of prompt injections, which involve embedding malicious instructions in emails or other untrusted content processed by large language models (LLMs).
ASCII smuggling employs a specific range of Unicode tags to render these instructions. For instance, the tag point U+E0041 mirrors the letter “A,” while U+E0061 mirrors “a.” This technique allows the malicious prompts to be detected by LLMs while remaining invisible to human readers.
Surge in Spam Activity
Earlier this year, Microsoft reported a significant increase in spam messages utilizing ASCII smuggling. In early February, the number of detected signatures surged from approximately 21,000 per day to over 1.3 million. Within just four days, detections rose to 2.5 million, with this trend continuing for several months before sharply declining in mid-May.
According to Microsoft, the invisibility of tag characters to humans, combined with their presence at the text-processing level, makes them effective for both smuggling instructions into models and obfuscating keywords from detection systems. This dual-use capability allows spammers to craft messages that do not raise user suspicions while still evading detection.
For more details, visit the full report by Ars Technica.
Follow Cyber Warriors Middle East for further global cybersecurity developments.



