Daud Jawad, Security Researcher at Fortra, is referenced in the Microsoft article ASCII smuggling crosses over from AI prompt injection to phishing evasion. Microsoft researchers identified a phishing campaign using invisible Unicode characters to evade detection and connected the activity to a broader SBA-themed phishing campaign previously documented by Fortra. The article highlights how threat intelligence research helps organizations understand how threat actors evolve campaigns and adopt new evasion techniques over time.
"After identifying the activity through this technique-specific signal, we connected it to a broader ActiveCampaign-delivered SBA-themed phishing campaign that Fortra had documented earlier. That earlier reporting indicates the campaign predated the adoption of Unicode tag character." -Microsoft