📣 Send us your press release
Site updates every 15 minutes
Technology

ASCII smuggling technique shifts from AI attacks to spam

A technique originally used to hide malicious prompts in AI attacks is now being adopted by spammers. ASCII smuggling embeds invisible characters that evade filters, facilitating mass unwanted email campaigns.

4 September 2026
ASCII smuggling technique shifts from AI attacks to spam

Spammers have begun employing ASCII smuggling, a technique previously known for its use in attacks targeting artificial intelligence. This method conceals malicious instructions within digital content, making it harder for email platforms' filters to detect and block unwanted mass messaging.

The ASCII smuggling technique leverages specific Unicode tags that closely mimic the American Standard Code for Information Interchange (ASCII). These tags encode characters that are readable by computers but virtually invisible to human readers. This allows harmful prompts to be embedded in a way that AI models can interpret, while human recipients remain unaware of any unusual content.

The technique first gained attention approximately two years ago as a means to make "prompt injection" attacks against AI models more stealthy. The goal was to compel AI systems to execute harmful commands without the malicious instructions being overtly visible in the input.

With its adoption by spammers, ASCII smuggling now poses an increased threat to email security. By effectively hiding malicious links or commands within spam messages, the technique can help bypass existing filters and improve the success rate of unsolicited campaigns.

Original source: arstechnica.com