< Back to all clusters
[TECHNOLOGY] · 3 sources

started · updated

AI and text salting techniques enhance phishing attacks

Cybersecurity researchers are observing a resurgence of “text salting” techniques used to bypass both traditional and AI-powered email security systems. In these campaigns, attackers embed large amounts of benign text, random stories, or invisible HTML filler within phishing emails. This tactic aims to dilute the ratio of suspicious language to safe language, tricking machine learning models and Large Language Models (LLMs) into assessing the email as legitimate. One specific method involves splitting keywords, such as inserting invisible characters between “pass” and “word,” to evade scanners while remaining readable to the recipient. Barracuda researchers reported detecting over one million phishing emails using these techniques since April.

Simultaneously, artificial intelligence is lowering the barriers for sophisticated social engineering. Attackers are now able to conduct highly personalized spear phishing at the scale of commodity spam by leveraging organizational data and social footprints. Beyond email, AI is accelerating “smishing” (SMS phishing) and the creation of deepfake audio and video, which are used to impersonate trusted individuals during critical moments, such as verifying fraudulent payment requests. Research indicates that identity-based attacks are increasingly difficult for legacy signature-based detection systems to intercept.

Entities

Barracuda · Verizon