started · updated
Cybersecurity researchers identify ‘text salting’ phishing tactic
Researchers have identified a widespread phishing tactic known as ‘text salting’ designed to bypass modern AI-driven email security systems. In over one million identified attacks, cybercriminals insert large amounts of random, harmless text into emails to dilute the impact of suspicious keywords like ‘urgent’ or ‘premium’.
To ensure the recipient only sees the intended fraudulent content, attackers use various methods to hide this extra text. These techniques include setting the font size of the ‘salt’ to zero, shrinking the visible display window, or shifting the text far to the right of the screen. By fragmenting HTML streams or embedding text directly within words, attackers aim to deceive security tools into classifying malicious messages as harmless.
Entities
Amazon · Barracuda · Counterfeit Crimes Unit · Europol · FBI