Microsoft researchers Noam Kochavi and Sarah Wolstencroft reported a significant phishing campaign on February 26 that pushed daily volumes to 2.37 million malicious messages.
Attackers utilized ASCII smuggling, a technique that inserts invisible Unicode characters into text to bypass security filters while remaining readable to human targets.
The findings, published on September 3, highlight how these non-rendering characters are used to break up words and evade detection systems in high-volume email attacks.