Phishers Hide “Funding” With Invisible Unicode

The Hacker News · Medium sophistication
Last updated September 4, 2026

Microsoft reported a real, high-volume phishing campaign (up to millions of emails per day) that hid key “loan/funding” lure words using invisible Unicode characters to slip past email filters. The emails used disposable finance-themed domains and were often routed through ActiveCampaign link-tracking domains, making them look more like legitimate marketing traffic.

Key findings

  • Microsoft observed a “high-volume phishing campaign” using invisible Unicode tag characters to bypass email filters.
  • Attackers split finance lure words (example: “funding”) with invisible characters so the text looks normal to recipients but won’t match filter signatures.
  • The campaign ran at very large scale (estimated weekday volumes between 1 and 2.37 million messages) and followed a weekday-heavy cadence.
  • The activity used “hundreds of disposable, finance-themed sender domains” and loan/line-of-credit/advance-funding style lures.
  • Links were routed through ActiveCampaign click-tracking domains (acemlnd[.]com and activehosted[.]com), potentially benefiting from the reputation of a legitimate marketing platform.

Who’s being targeted

  • Commonly targeted roles: Finance, Accounting, Executives, Small business support/sales teams, Anyone who reviews inbound loan/credit offers.
  • Affected industries: Small businesses (loan applicants), Finance (lending/loans), Any organization receiving business-loan themed email.
  • Attack channels: email.
  • Impersonated: A finance lender or funding provider using a finance-themed domain, An SBA-loan related sender using a marketing platform workflow.

Awareness takeaways

  • Treat unsolicited loan/credit/funding emails as high risk, verify with a trusted source before clicking or sharing business information.
  • Be cautious when links are routed through third-party click trackers; a reputable platform can still be abused by attackers.
  • Don’t assume “normal-looking” text is safe, attackers can use invisible characters to evade filtering and detection.

Red flags to watch for

  • Too-good-to-be-true loan/advance funding language that pressures fast action
  • Sender domain is a disposable, finance-themed lookalike rather than a known lender
  • Links are routed through tracking domains (e.g., acemlnd[.]com / activehosted[.]com)
  • Unsolicited request for sensitive business/financial data
  • Email appears like bulk marketing traffic rather than a known, verified SBA communication path
  • Use of AI-generated/phishing-style web flows that look tailored to the recipient
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

You get an email: “Your funding options are ready.” Looks like a normal loan offer, right? Microsoft spotted millions of these. They hide loan words like “funding” by splitting them with invisible Unicode, so filters miss it but your eyes don’t. The link often goes through acemlnd.com or activehosted.com, from some random loan domain, pushing you to share business and financial details. Aha moment: if a surprise loan or SBA email wants you to click a tracker link, stop, open your lender or SBA site yourself and check from there.

Similar attacks

Vishing Lures, Fake Identities, and Repo-Trap Attacks

Vishing Lures, Fake Identities, and Repo-Trap Attacks

This recap describes multiple real-world social-engineering-driven attacks, including vishing calls that push employees to spoofed login pages and a supply-chain trick where cloning/opening a GitHub repo in developer tools triggers malware. It also highlights an unusual case where an AI model…

August 10, 2026
Fake Zoom/Teams Calls Used to Steal Crypto Wallets

Fake Zoom/Teams Calls Used to Steal Crypto Wallets

North Korea-linked BlueNoroff is using fake Zoom and Microsoft Teams meeting pages shared from hijacked trusted contacts (often via Telegram) to trick victims into “updating” Zoom/Teams and running malicious commands. The phishing kit also fingerprints the victim’s browser to identify installed…

July 24, 2026
Fake Advisors, ClickFix, and Chrome Sync Spying

Fake Advisors, ClickFix, and Chrome Sync Spying

This roundup describes several real-world social-engineering and human-abuse techniques, including trojanized “installer” lures (ClickFix), large-scale phone-based investment fraud, and stalkers misusing Chrome Sync after brief physical access. The items include clear workflows that can be turned…

July 16, 2026
AI Voice “Apple Support” Phishing + Fake IT Helpdesk

AI Voice “Apple Support” Phishing + Fake IT Helpdesk

This news roundup describes real social-engineering operations where attackers impersonate trusted support teams to trick people into giving up secrets. One campaign uses email/SMS/WhatsApp plus AI voice calls pretending to be Apple Support to steal iPhone passcodes, while another uses phishing…

August 27, 2026
Fake Conferences Fuel OAuth and WhatsApp Phish

Fake Conferences Fuel OAuth and WhatsApp Phish

Google tracked three suspected Russia-linked groups running targeted phishing that abuses real login and authentication features (app passwords, OAuth, and device codes) to get into accounts. The lures often look like legitimate conference or diplomatic invitations, and some campaigns spoof…

August 21, 2026
Attackers Phish via Teams & Slack, Not Email

Attackers Phish via Teams & Slack, Not Email

Research and incident examples show attackers increasingly using trusted collaboration tools (like Microsoft Teams and Slack) to impersonate IT/support or known community members, then push victims to phishing sites, approve MFA prompts, or run malicious files. Because messages come through…

August 20, 2026