ASCII smuggling: Beyond merely a hassle with AI security

The Updated Function of ASCII Smuggling

Scammers have discovered a new troublemaker in ASCII smuggling. Rather than resorting to sophisticated AI security measures, they’re opting for the traditional method: email phishing. Microsoft revealed an extensive phishing operation utilizing concealed Unicode tag characters, peaking at more than 2.37 million messages in late February, keeping weekday employees alert for several months. By mid-June, it finally ceased.

AI Strategies in Conventional Threats

“As AI-era attack techniques become popular, wrongdoers may tweak them for the tried-and-true phishing and spam,” stated the insightful team at Redmond, Noam Kochavi and Sarah Wolstencroft, in a Thursday blog post. “This demonstrates how innovative tricks derived from AI security research can swiftly migrate into established attack territories. Makes you ponder, doesn’t it?”

What Exactly is ASCII Smuggling?

ASCII smuggling employs hidden or sneaky Unicode characters to insert suspicious content into text that appears as harmless as your grandmother’s tea cakes. This makes it a clever method for indirect prompt injection attacks. In these instances, an annoying attacker conceals instructions for an AI assistant within invisible Unicode characters, sneaking those troublesome prompts into a webpage or document. To a human, everything seems normal, but a model can detect the concealed text – and might just comply with the attacker’s wishes: leak data or escalate.

Phishing Emails Get the Concealed Treatment

Instead of leveraging ASCII smuggling for AI mischief, a cunning individual was observed by Microsoft’s security team using invisible Unicode characters to manipulate words in phishing emails. The objective appeared to be evading keyword filtering and content checks with a clever little tactic. Instead of stating “funding,” the attackers typed “fun⟨U+E0020⟩ding.”

Identified and Marked

“When we examined the flagged messages, the surprising find was the absence of smuggled instructions for an AI assistant,” noted Kochavi and Wolstencroft. “The invisible tag characters were utilized to break apart common financial keywords, prompting a literal signature or keyword match to reconsider.”

Major Phishing Operation Detected

Redmond initially detected this ASCII-smuggling signature in early February, highlighting approximately 21,000 messages on February 8 before it soared to an astonishing 1.3 million the following day. Most originated from around 150 finance-related domains, persisting into May before diminishing like a band past its peak.

Clear Weekday Trend

Security analysts identified two prominent characteristics: a plethora of emails during the weekdays with a weekend pause, and a gradual decrease after the initial frenzy. “Following a vigorous beginning, with weekday totals reaching 1 to 2.37 million messages, peaking on February 26, it gradually declined to about 80% less by late March.” After May 15, it fell even further, continuing sporadically until mid-June.

Protective Strategies

According to Redmond, defenders must ensure that normalization and tokenization processes adequately manage tag characters to combat the Unicode tag block threat. “Content intended for keyword, signature, or regex validation should have invisible and non-rendering Unicode code points thoroughly removed, so incorporating them into a word doesn’t mislead the match,” advised those threat-hunting experts.

Identify and Investigate

Microsoft also suggests monitoring behavioral indicators. “The activity had a distinctive rhythm: a surge of emails from discarded, finance-related temporary domains, adhering to a weekday pattern with precision,” cautioned Kochavi and Wolstencroft. “If you notice a sudden influx of tag-block characters from finance-themed senders, toggling on and off weekly, you may be onto a campaign.”

Overview

“Phish and Chips”

Indeed, even ASCII smuggling has adopted a vintage approach with a contemporary twist. Stay vigilant, or you may end up being the catch of the day!