Weekday volumes reached between 1 million and 2.37 million messages and the campaign hit its peak on February 26, 2026, according to Microsoft's analysis — a scale that turned a modest obfuscation trick into a mass-delivery problem.
Microsoft's finding: a high-volume phishing campaign and its rhythm
Microsoft's Security Research team described the activity as a "high-volume phishing campaign" that leaned on invisible Unicode tag characters to evade filters. The company reported the operation entered a high-volume phase that lasted roughly three months before dropping sharply after May 15, 2026. The traffic followed a clear weekly cadence: largely silent on weekends and resuming on Mondays, with weekday volumes estimated between 1 million and 2.37 million messages and a peak on February 26, 2026.
Microsoft also framed this campaign as an illustration that "AI-era evasion techniques can be adapted by threat actors in traditional phishing and spam campaigns."
ASCII Smuggling: the technique and the specific Unicode range
Microsoft labels the method "ASCII Smuggling." The technique inserts invisible or non-rendering Unicode characters into otherwise normal-looking text so that human-facing interfaces render ordinary words while automated detectors see altered byte sequences. The Windows maker called out a frequently abused range: the "Unicode Tags block, U+E0000 to U+E007F," noting it "contains a shadow copy of the printable ASCII characters (for example, U+E0041 mirrors 'A,' U+E0061 mirrors 'a')." Microsoft added that the block was "originally intended for language tagging and is now largely deprecated."
As Microsoft explained, the attackers inserted tag characters inside financial keywords so the text still reads normally to recipients and to parsing pipelines that drop or normalize the characters: "To a recipient, and to parsing pipelines that drop or normalize these characters, the word still reads as funding," Microsoft wrote. But to a detector matching the literal string or a regex that does not account for interleaved invisible code points, the contiguous keyword no longer appears — for example, "funding" becomes "fun⟨U+E0020⟩ding."

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scrambleDelivery: ActiveCampaign, disposable finance-themed domains, and click tracking
The campaign used hundreds of disposable, finance-themed sender domains to lure recipients with business-loan and advance-funding narratives. Microsoft published the top 10 sender domains by hits, including:
- guardiangrowthfunding[.]com
- digitalcapitalboost[.]com
- thebusinessloanexpress[.]com
- yourlocfunding[.]com
- advancefundingboost[.]com
- guardiancapitalway[.]com
- harboradvancefunding[.]com
- unitedfundingwave[.]com
- directcapitalboost[.]com
- onlinedirectfinance[.]com
Microsoft reported that these emails were relayed through the ActiveCampaign marketing and automation platform, which routed every outbound link via its own click-tracking domains: "acemlnd[.]com" and "activehosted[.]com." Microsoft warned that originating from a reputable marketing platform with "established IP reputation and authentication" can make malicious traffic resemble legitimate marketing traffic and "complicate reputation-based filtering."
ActiveCampaign told Microsoft it has tested its content-moderation systems with messages containing invisible Unicode characters and that such emails receive the same moderation verdict as their unobfuscated equivalents; it also said heavy use of the technique is treated as a "suspicious signal."
Prior disclosure: Fortra FIRE and the ActiveCampaign-enabled phishing playbook
The new Unicode-tagbed campaign dovetails with work published earlier: Fortra Intelligence and Research Experts (FIRE) disclosed details in September 2025 about a campaign that weaponized ActiveCampaign to distribute thousands of AI-generated phishing emails targeting Small Business Administration (SBA) loan applicants. FIRE said that operation focused on collecting detailed business and financial information to enable future, highly targeted spear-phishing.
FIRE highlighted the campaign's "ability to mass‑produce convincing, tailored websites that adapt to different illegitimate or impersonated domains" and noted that ActiveCampaign's AI-powered marketing automation features allowed threat actors to vary design, content, and flow — scaling more convincing phishing campaigns more quickly.
What this means for technologists, policymakers, and small businesses
Technologists and security teams: Microsoft’s technical description focuses attention on content parsing and signature models. The campaign shows that literal string matches and regexes that do not handle interleaved invisible code points can be bypassed; Microsoft’s finding also demonstrates how normalization behavior in parsing pipelines affects detection.
Policymakers and platform operators: The operation highlights how attacker use of shared marketing platforms with "established IP reputation and authentication" can complicate reputation-based filtering, a point Microsoft explicitly raised. ActiveCampaign’s statement that heavy use of invisible characters is a "suspicious signal" signals platform-level countermeasures are being applied, but Microsoft’s report underscores the tension between shared services and abuse detection.
Small businesses and loan applicants: The campaign amplified existing loan‑themed phishing patterns and used thousands of tailored messages and disposable domains to reach targets. Fortra FIRE’s September 2025 assessment said the earlier campaign collected detailed business and financial information, which suggests recipients of these lures should be wary of follow‑on, highly targeted attempts.
Microsoft’s disclosure ties a simple obfuscation technique to a large, structured delivery operation and to earlier, ActiveCampaign-enabled phishing that harvested business details. It leaves a clear operational picture: invisible Unicode tags were repurposed at scale, existing marketing infrastructure provided reach and perceived legitimacy, and the pattern produced millions of messages on weekdays before the volume waned in mid‑May 2026.
https://thehackernews.com/2026/09/phishing-campaign-sends-millions-of.html




