Large-Scale Phishing Campaign Uses Invisible Unicode and ActiveCampaign to Evade Email Security Filters

Large-Scale Phishing Campaign Uses Invisible Unicode and ActiveCampaign to Evade Email Security Filters

Executive Summary

A newly identified, large-scale phishing campaign is actively exploiting invisible Unicode characters to bypass traditional email security filters, sending millions of malicious emails globally. This campaign, tracked by Microsoft Security Research and corroborated by multiple industry sources, leverages ASCII smuggling and Unicode obfuscation—specifically, the insertion of invisible Unicode tag characters from the U+E0000–U+E007F range—within key phishing terms. By embedding these non-printable characters into words such as "funding" or "loan," attackers evade keyword-based and regex-based detection mechanisms, allowing their messages to reach user inboxes undetected. The campaign is notable for its unprecedented scale, technical sophistication, and use of reputable marketing automation platforms such as ActiveCampaign to distribute phishing emails. The primary targets are organizations in the financial, business, and healthcare sectors, with a focus on credential harvesting and business information theft. This report provides a comprehensive technical analysis, threat actor profile, exploitation details, victimology, and actionable mitigation strategies.

Threat Actor Profile

The threat actors behind this campaign have not been attributed to any known APT group or nation-state entity as of this writing. The operation is assessed as financially motivated, with a focus on large-scale credential harvesting, business email compromise, and potential follow-on fraud. The attackers demonstrate a high degree of operational security and technical acumen, leveraging hundreds of disposable, finance-themed sender domains and reputable marketing automation services to blend malicious traffic with legitimate marketing communications. Their tactics, techniques, and procedures (TTPs) align with MITRE ATT&CK techniques T1566.001 (Phishing: Spearphishing Attachment), T1566.002 (Phishing: Spearphishing Link), T1036 (Masquerading), T1027 (Obfuscated Files or Information), and T1140 (Deobfuscate/Decode Files or Information). The campaign’s infrastructure and cadence suggest a well-resourced, organized cybercriminal group with global reach.

Technical Analysis of Malware/TTPs

The core innovation in this campaign is the use of invisible Unicode tag characters (U+E0000–U+E007F), a deprecated Unicode block originally intended for language tagging. Attackers insert these characters into keywords commonly used in phishing lures, such as "funding," "loan," or "credit," resulting in obfuscated strings like "funding." To the human eye and most email clients, these words appear normal, but traditional email security solutions that rely on keyword or regex matching fail to detect them due to the interleaved invisible code points.

The emails are distributed via ActiveCampaign, an AI-powered marketing automation platform, which complicates reputation-based filtering and allows phishing emails to blend with legitimate marketing traffic. Outbound links are routed through ActiveCampaign click-tracking domains such as acemlnd[.]com and activehosted[.]com, further obfuscating the true destination of phishing URLs. The campaign’s infrastructure includes hundreds of finance-themed sender domains, with envelope sender patterns like "em-." and originating from the IP block 173.236.20[.]0/24.

The phishing emails typically lure recipients with themes related to business loans, lines of credit, or advance funding. The subject lines and message bodies are often MIME-encoded (RFC 2047), sometimes using Base64 encoding, and may include additional invisible characters such as the soft hyphen (U+00AD). The phishing links direct users to spoofed login pages hosted on compromised domains, designed to harvest credentials and sensitive business information.

Exploitation in the Wild

This campaign was first observed in early 2026, with activity peaking at up to 2.37 million emails sent per weekday. The attackers primarily target organizations in the financial, business, and healthcare sectors, with a global distribution and no specific country focus. The use of legitimate marketing automation services enables the attackers to bypass many traditional security controls, as these platforms are generally trusted by email gateways and security solutions.

The phishing infrastructure is highly dynamic, with hundreds of disposable sender domains and frequent rotation of click-tracking URLs. The attackers have demonstrated the ability to rapidly adapt their tactics in response to security community disclosures and platform countermeasures. For example, ActiveCampaign has updated its moderation systems to flag heavy use of invisible Unicode characters as suspicious, but the attackers continue to evolve their obfuscation techniques.

The impact of this campaign includes successful credential harvesting, business email compromise, and the collection of sensitive business and financial information. The scale and sophistication of the operation suggest that the stolen data may be used for future spear-phishing, fraud, or ransomware attacks.

Victimology and Targeting

The primary victims of this campaign are organizations in the financial, business, and healthcare sectors, with a particular focus on small and medium-sized enterprises (SMEs) applying for business loans or lines of credit. The attackers use finance-themed lures to increase the likelihood of user engagement, often impersonating legitimate financial institutions or government agencies such as the Small Business Administration (SBA).

The campaign is global in scope, with no specific country or region singled out for targeting. The use of reputable marketing automation platforms allows the attackers to reach a wide audience while minimizing the risk of detection and takedown. The phishing emails are tailored to appear as legitimate business communications, increasing the likelihood of successful credential theft and information compromise.

Mitigation and Countermeasures

To defend against this advanced phishing campaign, organizations should implement a multi-layered security strategy that includes both technical controls and user awareness training. Email security solutions must be updated to normalize or strip invisible Unicode tag characters (U+E0000–U+E007F) and soft hyphens (U+00AD) before applying keyword or regex-based filtering. Security teams should monitor for unusual spikes in finance-themed emails, especially those routed through ActiveCampaign infrastructure or containing suspicious encoding patterns.

Blocking known sender domains and click-tracking URLs such as acemlnd[.]com and activehosted[.]com at the email gateway and proxy levels can help reduce exposure. Behavioral analysis and AI-based detection should be employed to evaluate message structure and tone, not just keywords. Regular user training is essential to help staff recognize phishing lures, even when emails appear to come from reputable sources. Users should be encouraged to report suspicious emails, and organizations should conduct periodic phishing simulations to reinforce best practices.

Security teams should also leverage threat intelligence feeds and hunting queries to identify campaign activity based on infrastructure and content patterns. Collaboration with email service providers and industry partners can enhance detection and response capabilities.

References

About Rescana

Rescana is a leader in third-party risk management (TPRM), providing organizations with a comprehensive platform to assess, monitor, and mitigate cyber risks across their supply chain. Our advanced threat intelligence and automation capabilities empower security teams to proactively identify emerging threats and strengthen their cyber resilience. For more information about our TPRM solutions or to discuss your organization’s cybersecurity needs, we are happy to answer questions at info@rescana.com.