Affected Systems

Organizations using email security systems that rely on keyword matching and literal string detection. Campaign targets Small Business Administration (SBA) loan applicants and businesses seeking financing. Attackers abuse ActiveCampaign marketing platform (acemlnd[.]com, activehosted[.]com domains) to relay phishing emails from hundreds of disposable finance-themed sender domains.

Exploitation Status

Active exploitation confirmed. Campaign began February 2026, reached high-volume phase with 1-2.37 million messages daily on weekdays through mid-May 2026. Peak activity recorded February 26, 2026. Campaign follows weekly cadence with reduced weekend activity.

Business Impact

Email security controls using keyword-based detection fail to identify phishing emails containing invisible Unicode tag characters (U+E0000 to U+E007F block). Attackers split financial keywords like "funding" into "fun⟨U+E0020⟩ding" to evade filters while appearing normal to recipients. Emails originate from reputable ActiveCampaign infrastructure with established IP reputation, complicating reputation-based filtering. Campaign collects detailed business and financial information for future targeted spear-phishing attacks. High volume (millions daily) increases likelihood of successful compromise across SMB sector.

Urgency

🟠 Within 24 hours

Recommended Actions

  • Update email security rules to normalize or strip Unicode tag characters (U+E0000 to U+E007F block) before keyword matching and content analysis
  • Block or quarantine emails from known malicious finance-themed domains: guardiangrowthfunding[.]com, digitalcapitalboost[.]com, thebusinessloanexpress[.]com, yourlocfunding[.]com, advancefundingboost[.]com, guardiancapitalway[.]com, harboradvancefunding[.]com, unitedfundingwave[.]com, directcapitalboost[.]com, onlinedirectfinance[.]com
  • Implement detection rules for emails containing invisible Unicode characters combined with financial keywords (funding, loan, credit, advance, capital) and ActiveCampaign tracking domains (acemlnd[.]com, activehosted[.]com)
  • Conduct user awareness training focused on unsolicited business loan and SBA funding offers, emphasizing verification of sender legitimacy before clicking links or providing business information
  • Review email logs since February 2026 for messages containing Unicode tag characters and finance-related lures to identify potential compromises