Unicode-Smuggling Financial Phishing Evasion
An adversary is using invisible Unicode tag characters to split keywords in finance-themed phishing lures, bypassing traditional email filters and redirecting victims to disposable infrastructure.
Based on research by Microsoft 2026-09-20 12 steps · 4 queries T1090.003 T1566
Brief
Why now
Microsoft recently detailed a shift in tradecraft in their article ASCII smuggling crosses over from AI prompt injection to phishing evasion. Adversaries now use invisible characters to deceive both users and security filters. This hunt provides a structured way to find this crossover technique in your environment.
How the hunt flows
The hunt starts by narrowing the field to hosts that run Microsoft 365 or Office software. This scoping step ensures the analyst focuses on endpoints where users are most likely to interact with finance-themed email lures. The query builds an inventory of candidate hosts for the subsequent triage phases.
Next, the hunt looks for DNS activity related to known campaign-specific domains. These domains, such as guardiangrowthfunding.com, represent the first stage of the redirection chain. Any host that resolves these addresses becomes a primary lead. An analyst or automated agent then evaluates the volume and timing of these hits to decide which hosts merit a deeper inspection of their web traffic.
For hosts that pass the gate, the hunt runs two parallel checks to find corroborating evidence. The first query searches HTTP telemetry for specific percent-encoded markers—specifically the %f3%a0 prefix used for Unicode Tags. These markers often appear in the URL path or the Referrer header during the smuggling process. Simultaneously, a second query baselines the rarity of connections to the campaign domains across the entire fleet to confirm that the activity is an isolated incident rather than a connection to common shared infrastructure.
In the final phase, an analyst correlates the DNS leads with the HTTP-layer markers. If a host shows both the resolution of a campaign domain and the presence of smuggling characters in its web headers, the hunt provides an action to isolate the host. This prevents further lateral movement while a manual review confirms if the user successfully submitted credentials or downloaded a payload.
What the hunt cannot see
This hunt has two primary blind spots. First, if a host resolves campaign domains using DNS-over-HTTPS (DoH) or an unmonitored external resolver, the initial lead generation query will stay silent. Second, visibility into the percent-encoded smuggling markers depends on your ability to inspect HTTP traffic. If the traffic is encrypted and your environment lacks proxy-level inspection or host-based HTTP telemetry with full URL capture, the smuggling markers will remain hidden in the TLS stream.
Steps
-
Identify hosts with Office software
Query · scopingFocus the hunt on endpoints running software typically used for processing the phishing lures described in the research.
reads hb_software_inventorysqlSELECT device_hostname, package_name, package_version FROM hb_software_inventory WHERE (LOWER(package_name) LIKE '%microsoft 365%' OR LOWER(package_name) LIKE '%office%') GROUP BY device_hostname, package_name, package_versionWhat a hit looks like. A list of hostnames. Since this is an inventory snapshot, silence means no matching software was found on the monitored fleet.
-
DNS hits on campaign domains
Query · triageIdentify hosts that have interacted with the known campaign infrastructure as a primary lead.
reads hb_dns_activitysqlSELECT device_hostname, query_hostname, COUNT(*) as lookup_count, MIN(time) as first_hit, MAX(time) as last_hit FROM hb_dns_activity WHERE (instr(',' || '{{campaign_domains}}' || ',', ',' || LOWER(query_hostname) || ',') > 0) AND (('{{scope_hosts}}' = '') OR (instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0)) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY device_hostname, query_hostname ORDER BY lookup_count DESCWhat a hit looks like. Any hostname resolving the campaign domains is a lead. Silence suggests no direct interaction with the known IOC list occurred via monitored resolvers.
-
Evaluate DNS lead
Agent triageAnalyze the DNS activity to determine if a host shows meaningful interaction with the campaign infrastructure to justify deeper inspection.
-
Gate on lead verdict
DecisionOnly open expensive inspection queries for hosts that have already shown signs of campaign interaction.
-
HTTP smuggling check
Query · detection candidateIdentify HTTP requests where the URL or referrer contains the specific percent-encoded prefix for Unicode tag characters.
reads hb_http_activitysqlSELECT device_hostname, url_hostname, url_full, referrer, user_agent, time FROM hb_http_activity WHERE (LOWER(url_full) LIKE '%' || '{{encoded_tag_prefix}}' || '%' OR LOWER(referrer) LIKE '%' || '{{encoded_tag_prefix}}' || '%') AND (('{{scope_hosts}}' = '') OR (instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0)) AND time >= datetime('now', '-{{lookback_days}} days')What a hit looks like. A hit identifies the presence of the smuggling block in transit. This is a very rare and high-fidelity indicator of evasion tradecraft.
-
Network connection prevalence
Query · baselineEvaluate whether connections to the campaign domains are persistent and rare across the fleet.
reads hb_network_connectionsqlSELECT dst_endpoint_hostname, COUNT(DISTINCT device_hostname) as host_count, COUNT(*) as connection_count, MIN(time) as first_seen FROM hb_network_connection WHERE (instr(',' || '{{campaign_domains}}' || ',', ',' || LOWER(dst_endpoint_hostname) || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY dst_endpoint_hostname HAVING host_count <= 5 ORDER BY host_count ASC, connection_count DESCWhat a hit looks like. A low host count for a high-volume connection pattern confirms the domains are rare targets rather than legitimate shared infrastructure.
-
Final triage
Agent triageCorrelate the DNS lead with the HTTP-layer markers and network prevalence to reach a high-confidence verdict.
-
Route on final verdict
DecisionIsolate hosts with confirmed phishing interaction and route others for review.
-
Isolate host
Response actionPrevent further lateral movement or data exfiltration from a compromised endpoint.
-
Analyst review
Analyst taskReview the smuggling evidence and confirm if the user was successfully phished.
-
Close out
Analyst taskRecord results and update the campaign indicators.
Coverage
Scenario coverage
| Stage | Covered | How, or why not |
|---|---|---|
| Phishing Campaign Delivery T1566 |
Yes | dns-campaign-lead |
| Keyword Obfuscation via ASCII Smuggling T1566 |
Yes | http-smuggling-check |
| Multi-hop Proxy Redirection T1090.003 |
Yes | network-connection-pivot |
Blind spots
- Needs Endpoint DNS resolution logging. The lead query would fail to find the initial interaction, stopping the hunt at the gate. It would answer whether the host resolved a campaign domain using DoH or an unmonitored resolver.
- Needs hb_http_activity with full URL/Referrer capture. Encrypted traffic without proxy-level inspection prevents visibility into the percent-encoded smuggling markers in URL paths or referrers. It would answer whether the smuggling markers were present in encrypted HTTPS traffic.
Parameters & data
Parameters
| Parameter | Type | Default | What it is |
|---|---|---|---|
campaign_domains | list[domain] | guardiangrowthfunding.com, digitalcapitalboost.com, thebusinessloanexpress.com, yourlocfunding.com | Disposable finance-themed domains identified in the campaign. |
encoded_tag_prefix | string | %f3%a0 | The percent-encoded UTF-8 prefix for characters in the Unicode Tags block. |
lookback_days | number | 14 | Days of history to examine. |
scope_hosts | list[host] | — | Hosts with Microsoft 365 or Office installed, identified in the scoping step. |
Telemetry
| Source | Category | Telemetry |
|---|---|---|
| Endpoint telemetry (hb_ surfaces) | endpoint | endpoint |
| Network telemetry | network | network |
| Web server / proxy logs | siem | network |
Source
---
analysis: Simple keyword rules fail when terms like funding are split by invisible
characters. This hunt pivots across DNS, HTTP, and Network prevalence to confirm
the presence of percent-encoded smuggling markers that would be otherwise ignored
by static signatures.
blind_spots:
- id: no-dns-logging
question: whether the host resolved a campaign domain using DoH or an unmonitored
resolver
requires: Endpoint DNS resolution logging
risk: The lead query would fail to find the initial interaction, stopping the hunt
at the gate.
stage: phishing-campaign-delivery
- id: no-http-proxy
question: whether the smuggling markers were present in encrypted HTTPS traffic
requires: hb_http_activity with full URL/Referrer capture
risk: Encrypted traffic without proxy-level inspection prevents visibility into
the percent-encoded smuggling markers in URL paths or referrers.
stage: keyword-obfuscation-evasion
coverage:
- stage: phishing-campaign-delivery
status: covered
steps:
- dns-campaign-lead
- stage: keyword-obfuscation-evasion
status: covered
steps:
- http-smuggling-check
- stage: multi-hop-proxy-redirection
status: covered
steps:
- network-connection-pivot
guardrails:
claims: no_unsupported
evidence: citation_required
missing_data: not_benign
telemetry: untrusted
hunt:
applicability: campaign-specific
handoff: promote-to-detection
justification: Adversaries are repurposing AI prompt injection techniques for traditional
phishing evasion. These invisible characters successfully bypass keyword-based
filters; detecting this crossover tradecraft provides high-fidelity signals for
active fraud campaigns targeting financial assets.
methodology: model-assisted
trigger: intel-report
hypothesis: An adversary is using invisible Unicode tag characters to split keywords
in finance-themed phishing lures, bypassing traditional email filters and redirecting
victims to disposable infrastructure.
labels:
- hunt
- attack.t1566
- attack.t1090.003
name: Unicode-Smuggling Financial Phishing Evasion
parameters:
campaign_domains:
default:
- guardiangrowthfunding.com
- digitalcapitalboost.com
- thebusinessloanexpress.com
- yourlocfunding.com
description: Disposable finance-themed domains identified in the campaign.
from:
kind: article
observed: '2026-09-03'
ref: msrc-blog-ascii-smuggling
type: list[domain]
encoded_tag_prefix:
default: '%f3%a0'
description: The percent-encoded UTF-8 prefix for characters in the Unicode Tags
block.
type: string
lookback_days:
default: '14'
description: Days of history to examine.
type: number
scope_hosts:
default: []
description: Hosts with Microsoft 365 or Office installed, identified in the scoping
step.
type: list[host]
provenance:
authors:
- name: Huntbase hunt generation
org: huntbase.io
generated:
by: huntbase-hunt-generation
from: https://www.microsoft.com/en-us/security/blog/2026/09/03/ascii-smuggling-crosses-over-from-ai-prompt-injection-to-phishing-evasion/
gates:
- dry-run
- lint
- critic
model: hb_google/gemini-3-flash-preview
rationale: Targets hosts with Office/M365 installed as primary candidates for email-based
phishing interactions. The hunt assumes these hosts are the most likely to be targeted
with business-finance lures.
references:
- name: "MSRC Blog \u2014 ASCII smuggling crosses over from AI prompt injection to\
\ phishing evasion"
url: https://www.microsoft.com/en-us/security/blog/2026/09/03/ascii-smuggling-crosses-over-from-ai-prompt-injection-to-phishing-evasion/
related:
- hunt: homoglyph-phishing-domains
reason: That hunt focuses on visually similar characters in domain names, whereas
this hunt focuses on invisible smuggling characters inside keywords.
relation: out-of-scope-alternative
scenario:
stages:
- name: Phishing Campaign Delivery
observables:
- guardiangrowthfunding.com
- digitalcapitalboost.com
- thebusinessloanexpress.com
- yourlocfunding.com
- ActiveCampaign infrastructure
- Financial lures regarding business loans or line-of-credit
slug: phishing-campaign-delivery
tactic: initial-access
techniques:
- T1566
- name: Keyword Obfuscation via ASCII Smuggling
observables:
- Unicode tag characters range U+E0000 to U+E007F
- Invisible TAG SPACE U+E0020
- Split keywords like 'f<U+E0020>unding'
- Invisibility in human-facing UI while appearing to machine parsers
slug: keyword-obfuscation-evasion
tactic: defense-evasion
techniques:
- T1566
- name: Multi-hop Proxy Redirection
observables:
- Disposable finance-themed domains
- Multi-hop proxy infrastructure to disguise traffic source
slug: multi-hop-proxy-redirection
tactic: command-and-control
techniques:
- T1090.003
summary: A high-volume phishing campaign leveraged invisible Unicode tag characters
(ASCII Smuggling) to split financial keywords such as 'funding' in email lures,
successfully evading literal keyword filters and NLP-based tokenizers. The campaign
utilized over 150 finance-themed domains and followed a strict weekday-only cadence
for three months starting in February 2026.
severity: high
targets:
analyst:
name: Tier-2 analyst
role: analyst
endpoint:
category: endpoint
name: Endpoint telemetry (hb_ surfaces)
telemetry:
- endpoint
hunter:
agent: true
name: Hunt agent
network:
category: network
name: Network telemetry
telemetry:
- network
web:
category: siem
name: Web server / proxy logs
telemetry:
- network
tlp: clear
type: investigation
---
# Unicode-Smuggling Financial Phishing Evasion
This hunt identifies the use of ASCII smuggling characters (U+E0000 to U+E007F) within phishing campaigns targeting financial departments. By inserting invisible TAG characters into lure words like funding, attackers evade literal keyword matching and modern NLP-based classifiers. The hunt uses a gated flow to first identify interactions with campaign-specific domains before performing a deep dive into HTTP headers for percent-encoded smuggling markers and corroborating the activity with network connection patterns that suggest multi-hop redirection.
## scoping-office-hosts
<!-- Identify hosts with Office software -->
Focus the hunt on endpoints running software typically used for processing the phishing lures described in the research.
```sqlite target=endpoint role=scoping
~~~yaml
expected: A list of hostnames. Since this is an inventory snapshot, silence means
no matching software was found on the monitored fleet.
reads:
- device_hostname
- package_name
- package_version
silence: not_evidence_of_absence
source: hb_software_inventory
verified: dry-run
verified_at: '2026-09-20'
~~~
SELECT device_hostname, package_name, package_version FROM hb_software_inventory WHERE (LOWER(package_name) LIKE '%microsoft 365%' OR LOWER(package_name) LIKE '%office%') GROUP BY device_hostname, package_name, package_version
```
## dns-campaign-lead
<!-- DNS hits on campaign domains -->
Identify hosts that have interacted with the known campaign infrastructure as a primary lead.
```sqlite target=endpoint role=triage params=(campaign_domains=campaign_domains, scope_hosts=scope_hosts, lookback_days=lookback_days)
~~~yaml
expected: Any hostname resolving the campaign domains is a lead. Silence suggests
no direct interaction with the known IOC list occurred via monitored resolvers.
reads:
- device_hostname
- query_hostname
- time
silence: not_evidence_of_absence
source: hb_dns_activity
verified: dry-run
verified_at: '2026-09-20'
~~~
SELECT device_hostname, query_hostname, COUNT(*) as lookup_count, MIN(time) as first_hit, MAX(time) as last_hit FROM hb_dns_activity WHERE (instr(',' || '{{campaign_domains}}' || ',', ',' || LOWER(query_hostname) || ',') > 0) AND (('{{scope_hosts}}' = '') OR (instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0)) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY device_hostname, query_hostname ORDER BY lookup_count DESC
```
## evaluate-lead
<!-- Evaluate DNS lead -->
```agent target=hunter
cite: required
context:
- dns-campaign-lead
max_iterations: 3
objective: Determine if the DNS lookups in dns-campaign-lead represent a suspicious
interaction with confirmed campaign domains.
success_criteria: A per-host verdict of suspicious or benign.
tools:
- endpoint
- network
- web
```
## gate-on-lead
<!-- Gate on lead verdict -->
if~: "the evaluate-lead verdict identifies at least one host with suspicious domain resolutions" (confidence: high, judge=hunter)
then: → deep-dive-checks
indeterminate: → analyst-review
unavailable: → analyst-review (blind_spot: no-dns-logging)
else: → close-out
## deep-dive-checks
<!-- Parallel corroboration -->
parallel:
- → http-smuggling-check
- → network-connection-pivot
join: → final-triage
## http-smuggling-check
<!-- HTTP smuggling check -->
Identify HTTP requests where the URL or referrer contains the specific percent-encoded prefix for Unicode tag characters.
```sqlite target=web role=detection-candidate params=(encoded_tag_prefix=encoded_tag_prefix, scope_hosts=scope_hosts, lookback_days=lookback_days)
~~~yaml
expected: A hit identifies the presence of the smuggling block in transit. This is
a very rare and high-fidelity indicator of evasion tradecraft.
reads:
- device_hostname
- url_hostname
- url_full
- referrer
- time
silence: not_evidence_of_absence
source: hb_http_activity
verified: dry-run
verified_at: '2026-09-20'
~~~
SELECT device_hostname, url_hostname, url_full, referrer, user_agent, time FROM hb_http_activity WHERE (LOWER(url_full) LIKE '%' || '{{encoded_tag_prefix}}' || '%' OR LOWER(referrer) LIKE '%' || '{{encoded_tag_prefix}}' || '%') AND (('{{scope_hosts}}' = '') OR (instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0)) AND time >= datetime('now', '-{{lookback_days}} days')
```
## network-connection-pivot
<!-- Network connection prevalence -->
Evaluate whether connections to the campaign domains are persistent and rare across the fleet.
```sqlite target=network role=baseline params=(campaign_domains=campaign_domains, lookback_days=lookback_days)
~~~yaml
baseline:
compare: first_seen
window: '{{lookback_days}}d'
expected: A low host count for a high-volume connection pattern confirms the domains
are rare targets rather than legitimate shared infrastructure.
prevalence:
by: device_hostname
key:
- dst_endpoint_hostname
rare_below: 5
reads:
- dst_endpoint_hostname
- device_hostname
- time
silence: not_evidence_of_absence
source: hb_network_connection
verified: dry-run
verified_at: '2026-09-20'
~~~
SELECT dst_endpoint_hostname, COUNT(DISTINCT device_hostname) as host_count, COUNT(*) as connection_count, MIN(time) as first_seen FROM hb_network_connection WHERE (instr(',' || '{{campaign_domains}}' || ',', ',' || LOWER(dst_endpoint_hostname) || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY dst_endpoint_hostname HAVING host_count <= 5 ORDER BY host_count ASC, connection_count DESC
```
## final-triage
<!-- Final triage -->
```agent target=hunter
cite: required
context:
- evaluate-lead
- http-smuggling-check
- network-connection-pivot
max_iterations: 4
objective: Determine if any host successfully established communication with the campaign
infrastructure using ASCII smuggling techniques.
success_criteria: A per-host verdict of malicious, suspicious, or benign.
tools:
- endpoint
- network
- web
```
## route-remediation
<!-- Route on final verdict -->
if~: "the final-triage verdict is malicious for at least one host" (confidence: high, judge=hunter)
then: → contain-host
indeterminate: → analyst-review
unavailable: → analyst-review (blind_spot: no-http-proxy)
else: → close-out
## contain-host
<!-- Isolate host -->
```action target=endpoint
~~~yaml
approval: required
~~~
Isolate the host and terminate any active network sessions to the campaign domains.
```
→ analyst-review
## analyst-review
<!-- Analyst review -->
```manual target=analyst
Review the HTTP referrer and full URL columns for the smuggling prefix. Confirm if the interaction resulted in a login attempt or file download. Check for related emails in the user's inbox to identify new lure keywords.
```
→ close-out
## close-out
<!-- Close out -->
```manual target=analyst
Document the hosts examined. If new campaign domains were found, add them to the campaign_domains parameter for future runs.
```
→ end
Run it
Take this hunt into your environment.
Open it in Huntbase to run every step against your own connections, with Scout weighing the evidence and your analysts in command. Or take the open hunt.md file anywhere that reads the format.
Machine-drafted by huntbase-hunt-generation using hb_google/gemini-3-flash-preview, gated by dry-run, lint, critic, then reviewed by a person.