Once popular for attacking AI, ASCII smuggling is embraced by spammers
Attackers are repurposing ASCII smuggling—a technique first used to hide malicious AI prompts—to evade modern spam and phishing filters, exposing a blind spot in email security controls that rely on text matching and NLP/ML classification. For CIOs and technology leaders, this is a reminder that adversaries are adapting faster than content-based defenses, increasing the risk of successful phishing, business email compromise, and other social-engineering attacks if filters do not normalize and inspect hidden Unicode. IT organizations should assume current detection stacks may be bypassed by obfuscation tricks and prioritize layered controls, including normalization, Unicode-aware filtering, and image/OCR-based analysis where appropriate.
