< Back to situations

Monitor this situation.

[SITUATION] · [QUIET] · [TECHNOLOGY]

2 clusters · 8 sources · 10 days · First seen · Last updated

Email phishing evasion and security evolution

Overview

Cybersecurity researchers have identified evolving phishing tactics designed to bypass AI-driven email security systems. One method, known as ‘text salting’, involves inserting large amounts of random, harmless text into emails to dilute suspicious keywords. Attackers hide this extra text by using zero-sized fonts, shrinking display windows, or shifting text off-screen to ensure the recipient only sees the fraudulent content.

Further developments include ‘ASCII smuggling’, a technique where invisible Unicode characters are used to break up suspicious words. This method allows malicious messages to appear normal to human readers while disrupting the ability of automated filters and machine learning systems to recognize them.

Threat actors are also increasingly utilizing exotic file formats, such as ISO disk images, to bypass endpoint detection and response (EDR) and email protection solutions. These files can be mounted natively by operating systems, avoiding the need for suspicious user actions like decompression.

To counter these threats, security standards like SPF, DKIM, and DMARC are critical. As of May 2026, DMARC has become an official IETF standard (RFC 9989), though effective protection requires implementing quarantine or rejection policies rather than mere observation. Additional protocols such as MTA-STS and DANE are also used to enforce transport encryption. In response to AI-generated attacks and complex SaaS ecosystems, new intelligence platforms are being launched to provide unified visibility and governance across evolving email infrastructures.

Entities

FBI · EasyDMARC · Barracuda · Microsoft · Counterfeit Crimes Unit

Timeline

  1. [TECHNOLOGY] 5 sources
    Email security faces rising threats from exotic file formats and AI-driven attacks

    Cybercriminals are using exotic file formats like ISO images to bypass email security. Experts emphasize the importance of DMARC standards and new AI-driven intelligence platforms to combat evolving phishing.

  2. [TECHNOLOGY] 3 sources
    Cybersecurity researchers identify ‘text salting’ phishing tactic

    Researchers have uncovered a ‘text salting’ phishing technique where hidden, random text is used to trick AI-powered email security filters into overlooking fraudulent content.

Sources

b2b-cyber-security.de · blog.kaspersky.fr · cyber-securite.fr · ledecodeur.ch · presseportal.de · skiline.cc · techbook.de · techno-science.net

This summary has been updated 1 time: see revision history