Barracuda identifies over one million phishing attacks using ‘text salting’ evasion technique
https://etimg.etb2bimg.com/thumb/msid-132454744,imgsize-23594,width-1200,height=627,overlay-etciso,resizemode-75/ot-security/barracuda-identifies-over-one-million-phishing-attacks-using-text-salting-evasion-technique.jpg
Barracuda researchers have identified more than one million retail-themed phishing attacks employing a technique known as “text salting” to evade email security tools, according to a new report.
Text salting involves inserting large amounts of unrelated, benign text into phishing emails and hiding it from recipients while keeping it visible to email scanners. The technique is designed to reduce the prominence of suspicious keywords and phrases that traditional spam filters and AI-based security systems use to identify malicious emails.
The report found that attackers concealed the additional text using several methods, including shrinking the visible display area, indenting text outside the visible frame, inserting zero-font-size text within words or sentences, and fragmenting HTML content to disrupt signature-based detection.
For example, a phrase such as “Your password expired” could be split by hidden text embedded with a zero-size font, preventing scanners from matching the expected phrase while remaining unchanged to the recipient.
The hidden content typically consisted of unrelated material such as stories, project notes, or conversational text containing common, benign words including “puppy,” “training,” “notes,” “task,” “rhythm,” and “book.” The visible portion of the email, meanwhile, presented retail-themed lures such as expiring reward points, gift cards, or loyalty offers intended to prompt immediate action.
According to Barracuda, researchers have observed increased use of text salting over the past year, with attackers adapting the technique to evade not only traditional keyword-based detection but also machine learning models and large language model (LLM)-based email security systems.
The report notes that LLM-based security tools process all available email content, including hidden text, when assessing an email’s intent and risk. Large volumes of benign hidden content can influence these models to classify phishing emails as legitimate. The availability of generative AI also enables attackers to automatically generate large volumes of unique, natural-sounding text, making phishing campaigns more varied and difficult to detect using pattern-based techniques.
Barracuda recommends a layered email security approach that combines message structure analysis, sender reputation, behavioural monitoring, authentication checks, embedded link analysis, HTML rendering inspection, and evaluation of user-visible content, rather than relying solely on keyword detection. The company also advises continued user awareness training to help employees identify common phishing indicators, including unsolicited offers and messages creating a false sense of urgency.
Firewall Support Company in India All type of Firewalls Support Provider Company in India












