\n\n\n\n Spam's Newest Trick Is Made Of Nothing At All - Agent 101 \n

Spam’s Newest Trick Is Made Of Nothing At All

📖 5 min read•858 words•Updated Sep 7, 2026

The most interesting thing about AI-era attack techniques isn’t what they do to AI. It’s how fast ordinary criminals steal them and point them at us instead.

That’s the story buried in a piece of security news that got filed under “AI threats” and probably deserves a different label entirely. ASCII smuggling, a trick that made its name as a way to slip hidden instructions past chatbots, has been picked up by email spammers. Microsoft says its use climbed sharply starting in February 2026. The technique itself hasn’t changed much. The target has. And the target is now your inbox.

What ASCII smuggling actually is

Let’s keep this plain, because the concept is simpler than the name suggests.

Text on a computer isn’t really letters. It’s numbers that software agrees to draw as letters. That agreement is called Unicode, and it covers an enormous range of characters: every alphabet you can think of, emoji, symbols, and a lot of oddities that exist for technical reasons rather than human ones.

Some of those oddities don’t draw anything at all. They’re valid characters that your screen renders as absolutely nothing. To you, a message containing them looks like a normal sentence. To a program reading the raw data, there’s extra content sitting right there in the text, plain as day.

ASCII smuggling means hiding meaningful content inside those invisible characters. One message, two readers, two completely different experiences. That gap between what humans see and what machines read is the whole attack.

Round one was about tricking AI

The first popular use was prompt injection. If you can hide text that a person won’t notice but an AI assistant will read, you can smuggle instructions into a document, a web page, or an email and hope the assistant treats them as commands from its user.

This matters for anyone using AI agents, which is why we talk about it here. An agent that summarizes your email or browses on your behalf is reading raw content, not looking at a rendered screen the way you do. It sees everything. Invisible characters included.

Microsoft’s discovery came out of research into exactly that problem, prompt injection protection work in Defender for Office 365. Which is a nice reminder that defensive research often surfaces things nobody was looking for.

Round two is about tricking filters

Here’s what makes the crossover clever, in a grim way. Email spam filters are pattern matchers. They look for known bad links, suspicious phrases, brand names used in ways that suggest impersonation, and thousands of other signals. They’re good at it, which is why most junk mail never reaches you.

But pattern matching depends on the pattern being recognizable. Sprinkle invisible characters through a suspicious word and the filter may no longer recognize the word. The human recipient still reads it perfectly, because the invisible parts are, well, invisible. The filter sees gibberish it has no rule for. You see a convincing message from your bank.

Same technique, flipped purpose. Round one made machines read something extra. Round two makes machines fail to read something obvious. Both exploit the same gap.

Why this pattern is going to keep repeating

I want to zoom out, because the specific trick matters less than what it demonstrates.

AI security research is producing a steady supply of new techniques for confusing software that reads text. Prompt injection, hidden instructions, character-level manipulation, encoding games. These get discussed as AI problems, published in AI contexts, and tracked by AI safety teams.

Spammers read that research too. And they have a large, established business built on confusing software that reads text. The moment a technique proves it can fool one kind of text-processing system, someone tests it against every other kind. There was no reason to expect a firewall between the two worlds, and there isn’t one.

So the practical lesson for non-technical readers is not “learn about Unicode.” It’s this: any defense built on recognizing text can be attacked by messing with how that text is encoded. That applies to spam filters, content moderation, AI assistants, and the agent you just gave access to your calendar.

What you can reasonably do

Not much at the character level, honestly, and that’s fine. This is a job for the platforms, and Microsoft flagging the increase is a sign that detection is catching up.

What you can do is adjust your instincts:

  • Treat “it got past the spam filter” as weak evidence of legitimacy. It was always weak. It’s weaker now.
  • Verify requests for money, credentials, or urgent action through a channel you chose, not one the message handed you.
  • Be skeptical of AI agents that act on incoming content automatically. Reading your email is one risk level. Acting on it is another.
  • Keep your email client and browser updated, since encoding-level fixes arrive quietly in these updates.

A block of characters that displays as nothing turned out to be useful to two very different groups of attackers within a few years of each other. That’s not an AI story or an email story. It’s a story about how quickly good ideas travel, regardless of who thought of them first.

🕒 Published:

🎓
Written by Jake Chen

AI educator passionate about making complex agent technology accessible. Created online courses reaching 10,000+ students.

Learn more →
Browse Topics: Beginner Guides | Explainers | Guides | Opinion | Safety & Ethics
Scroll to Top