Spam Campaign Leverages ASCII Smuggling Technique
ASCII smuggling, a technique used to hide instructions in invisible Unicode characters, has been repurposed for malicious purposes. Microsoft discovered that someone was using this method to split words in spam emails, specifically the word 'funding', making it difficult for filters to detect.
The campaign, which ran from February 8 to June 15, pushed millions of messages per weekday, with a peak of over 2.3 million on February 11, according to Microsoft's own post. However, the team found that more than 99% of the messages were caught by existing security measures, including sender and IP reputation checks, URL and domain checks, and brand impersonation detection.
The campaign used a vocabulary of 28 words to create disposable domains, with some taking over 30,000 hits per day. The technique was relayed through ActiveCampaign, a legitimate marketing platform, which rewrites links to route through its own tracking domains. Microsoft advises stripping or folding invisible code points out of email text before filtering.