For two years, invisible Unicode characters have been the neat trick of AI security research. You hide instructions inside them. A person sees nothing. A language model reads them and does as it is told.
Microsoft has now found somebody using the same characters for something far less clever. They were splitting up the word “funding” in spam.
Noam Kochavi and Sarah Wolstencroft of Microsoft Security Research published the finding in a blog post on Thursday. At its height the campaign pushed millions of messages a weekday.
The block of characters nobody wanted
The technique is called ASCII smuggling. It uses the Unicode Tags block, U+E0000 to U+E007F. That block holds an invisible shadow copy of the printable ASCII characters. U+E0041 mirrors a capital A. U+E0061 mirrors a lowercase one.









