Cyberattackers have devised a sneaky way to evade email security filters, exploiting a weakness in artificial intelligence-powered detection tools. Since April, over 1 million retail-themed phishing emails have slipped into inboxes, using hidden text to make malicious social engineering appear legitimate.
These emails are not just any ordinary spam messages. They employ obvious social engineering tricks, promising rewards and gift cards to targets. However, it’s the use of “text salting” that allows them to evade detection. Text salting involves peppering spam content with innocuous words or stories to break up malicious language. The goal is to make the email look legitimate to automated security filters while remaining suspicious to human eyes.
The emails Barracuda researchers have observed are typically well-versed in standard authentication protocols, such as DomainKeys Identified Mail (DKIM). This suggests that attackers are aware of industry-standard security measures and have found ways to bypass them. The security guard for email inboxes, known as secure email gateways (SEGs), relies on a combination of rule-based checks and machine-learning algorithms to filter out malicious emails.
However, when it comes to interpreting content, SEGs often fall short. They rely on filtering specific phrases or word usage patterns associated with spammy language. But attackers have found ways to evade these filters by manipulating the HTML code underpinning the email. By peppering the email with innocuous words and stories, they can make it appear legitimate while hiding malicious content from sight.
One of the most effective techniques used by attackers is “overflowing” text off-screen or hiding it within a viewing window with zero height and width. Modern security tools have learned to detect hidden text, but hackers have responded by layering multiple salting techniques on top of each other. This makes it increasingly difficult for SEGs to catch malicious emails.
The rise of large language models (LLMs) has given attackers an asymmetric advantage in evading AI-powered detection tools. LLMs can generate complex and seemingly legitimate text, making it harder for security filters to distinguish between good and bad content. As a result, attackers are using these techniques to dupe even the most sophisticated email security filters.
So what does this mean for consumers? It’s essential to remain vigilant when checking your emails. If you receive an email with suspicious language or attachments, don’t click on it – report it to your IT department immediately. Additionally, ensure that your SEGs are up-to-date and configured correctly to detect hidden text. This may involve implementing additional security measures, such as using machine-learning algorithms specifically designed to detect text salting techniques.
Ultimately, the cat-and-mouse game between attackers and email security filters will continue. But by being aware of these tactics and taking proactive steps to protect yourself, you can reduce your risk of falling victim to phishing attacks.
Source: Dark Reading — 2026-07-16