A trick once used to attack AI models is now being used by email spammers

Started by KeyboardWarrior, Today at 08:28 AM

Previous topic - Next topic

0 Members and 1 Guest are viewing this topic.

Topic: A trick once used to attack AI models is now being used by email spammers   Views(Read 82 times)
Active members in this topic:
KeyboardWarrior(1)

KeyboardWarrior

Microsoft researchers identified a high-volume phishing campaign using invisible Unicode tag characters, a technique called ASCII smuggling that was originally popularized through research into prompt injection attacks against AI systems. The Unicode Tags block, a range of code points from U+E0000 to U+E007F, contains shadow representations of ordinary printable characters that aren't rendered by typical fonts or interfaces, meaning a person sees nothing while any software processing the raw text, including a language model, still reads the hidden characters

In the original AI security context, attackers would hide entire instructions inside these invisible characters on a webpage, document or email, letting an AI assistant execute a command a human reader would never see at all. Microsoft found spammers repurposed the same technique for a different purpose, splitting suspicious financial lure words like funding with invisible tag characters so email filters couldn't recognize the word as a single unbroken string, even though a human reading the email would see it displayed normally. Detections of this specific evasion technique spiked sharply starting February 9th and stayed elevated on weekdays for roughly three months, generating millions of daily messages through a large network of rotating sender domains

Microsoft's research team discovered the campaign while specifically hunting for AI-targeted prompt injection content in Microsoft Defender for Office 365, only to find the exact same underlying character range being abused for an entirely different, more mundane purpose. Curious what people think this specific crossover reveals, does the fact that AI security research techniques are already leaking into ordinary spam and phishing mean AI adjacent security work needs to think more defensively from the start

Press F to pay respects

Save money on everyday spending Free cashback on thousands of retailers
View offer