Attackers hide random text in phishing scams by setting font size to zero to confuse AI powered email defenses
Barracuda researchers have detected more than a million phishing attacks using an evasion tactic developed years ago to bypass traditional spam filters by diluting the impact of suspicious words. A new report details how the tactic, known as ‘text salting,’ involves inserting large volumes of unrelated, benign text into an email and then hiding it in a way that allows it to be scanned by security tools while remaining invisible to the email recipient – who sees only the intended phishing content.
The goal is to trick security tools into classifying the email as harmless by disrupting red flag phrases or watering down the concentration of scam-associated words such as “urgent,” “rewards”, “expires” etc.
In their analysis of the retail-themed scam, Barracuda researchers found text salting techniques that included reducing the visible viewing window by 100% or indenting the text So far to the right of the frame that it...
Copyright of this story solely belongs to itvoice.in. To see the full text click HERE