Spammers adopt ASCII smuggling technique once used against AI systems

A long-known trick that hides text in plain sight is now a common tool for evading email filters.
A technique that was once associated with adversarial attacks on large language models is now showing up in everyday spam campaigns. The method, known as ASCII smuggling, exploits certain Unicode characters that are visually indistinguishable from ordinary letters but carry different underlying code points. Because these characters are not recognized by many text-processing systems, they can be used to slip deceptive content past filters that rely on standard character matching.
Security researchers have observed a marked increase in the use of this obfuscation tactic across spam emails, particularly those designed to impersonate trusted brands or deliver phishing links. The approach works by embedding lookalike characters from non-Latin scripts or using zero-width joiners and other invisible markers. While AI chatbots were initially the primary target—since they could be tricked into ignoring malicious instructions hidden this way—spammers have now realized the same trick can fool conventional email scanners.
The shift highlights a broader trend where techniques developed for attacking machine learning systems are being repurposed for more mundane cybercrime. Email providers are updating their filters to detect these unusual character sequences, but the arms race is ongoing. As the technique becomes more widespread, experts warn that users should remain cautious of messages that seem slightly off, even if they pass automated checks.