High-volume Unicode-smuggling phishing campaign
Campaign
Summary
Hide ▲
Show ▼
A high-volume phishing campaign is using invisible Unicode tag characters to split lure words and bypass email filters, pushing finance-themed emails at scale. The activity first surfaced in early February 2026 and later reached 1 to 2.37 million messages on weekdays. A broader linked operation used ActiveCampaign to distribute AI-generated phishing emails targeting Small Business Administration loan applicants. The evasion technique increases the odds that malicious emails reach recipients and can complicate reputation-based filtering.
Related Happenings
SVG voicemail phishing campaign
Campaign
H score42
First: 28.08.2026 16:00
Last: 28.08.2026 16:00
Sources 1
About this happening:
The SVG voicemail phishing campaign is a broad-spray operation that delivered 26,589 messages to 5,527 organizations, increasing the chance of email-defense bypass and...
SVG voicemail phishing campaign
CampaignAbout this happening: The SVG voicemail phishing campaign is a broad-spray operation that delivered 26,589 messages to 5,527 organizations, increasing the chance of email-defense bypass and...
Phishing becomes dominant initial access vector across Cisco Talos incident-response investigations, March-June 2026
Trend
H score30
First: 28.07.2026 16:00
Last: 28.07.2026 16:00
Sources 1
About this happening:
Phishing became the dominant initial access vector across incident-response investigations in March to June 2026, raising the risk of credential theft and follow-on co...
Phishing becomes dominant initial access vector across Cisco Talos incident-response investigations, March-June 2026
TrendAbout this happening: Phishing became the dominant initial access vector across incident-response investigations in March to June 2026, raising the risk of credential theft and follow-on co...
UAT-11764 QR code phishing campaign against organizations
Campaign
H score29
First: 28.07.2026 16:00
Last: 28.07.2026 16:00
Sources 1
About this happening:
A persistent QR code phishing campaign attributed to UAT-11764 is stealing Microsoft 365 credentials from organizations and reusing compromised mailboxes for follo...
UAT-11764 QR code phishing campaign against organizations
CampaignAbout this happening: A persistent QR code phishing campaign attributed to UAT-11764 is stealing Microsoft 365 credentials from organizations and reusing compromised mailboxes for follo...
The Quarry PaaS ecosystem and RockyBelling's promotion of MaDoO Blaster
Threat Actor Meta
H score14
First: 13.07.2026 18:30
Last: 13.07.2026 18:30
Sources 1
About this happening:
The Quarry was tied to MaDoO Blaster, showing a phishing-as-a-service ecosystem that packages AiTM tooling for sale. The operation was run by RockyBelling, who pro...
The Quarry PaaS ecosystem and RockyBelling's promotion of MaDoO Blaster
Threat Actor MetaAbout this happening: The Quarry was tied to MaDoO Blaster, showing a phishing-as-a-service ecosystem that packages AiTM tooling for sale. The operation was run by RockyBelling, who pro...
GreyVibe AI-assisted cyberespionage campaign targeting Ukraine-linked organizations
Campaign
H score39
First: 29.05.2026 01:24
Last: 29.05.2026 01:24
Sources 1
About this happening:
GreyVibe is running an AI-assisted cyberespionage campaign against Ukrainian and Ukraine-related organizations, expanding the threat to military, government, civilian,...
GreyVibe AI-assisted cyberespionage campaign targeting Ukraine-linked organizations
CampaignAbout this happening: GreyVibe is running an AI-assisted cyberespionage campaign against Ukrainian and Ukraine-related organizations, expanding the threat to military, government, civilian,...
Timeline
-
04.09.2026 18:57 2 articles · 13h ago
Unicode-smuggling phishing campaign peaks at 1 to 2.37 million weekday messages
Campaign Scope UpdateOn February 26, 2026, the phishing operation reached its peak weekday volume of 1 to 2.37 million messages while using finance-themed sender domains and ActiveCampaign relays to route click-tracking links through "acemlnd[.]com" and "activehosted[.]com". The campaign used lure patterns such as business loan, line-of-credit, and advance-funding messages to push phishing at scale.
Show sources
- Phishing Campaign Sends Millions of Emails Using Invisible Unicode to Evade Filters — thehackernews.com — 04.09.2026 18:57
- Phishing Campaign Sends Millions of Emails Using Invisible Unicode to Evade Filters — thehackernews.com — 04.09.2026 18:57
-
04.09.2026 18:57 1 articles · 13h ago
Microsoft warns of phishing emails using Unicode tag characters to evade filters
Initial DisclosureMicrosoft warned that a high-volume phishing campaign used invisible Unicode tag characters from the Unicode Tags block U+E0000 to U+E007F to split financial lure words such as "funding" and bypass keyword- and literal-based email filters. The technique makes the text appear normal to recipients while complicating reputation-based filtering and can be adapted to traditional phishing and spam campaigns.
Show sources
- Phishing Campaign Sends Millions of Emails Using Invisible Unicode to Evade Filters — thehackernews.com — 04.09.2026 18:57