Cybercriminals are increasingly employing a technique known as “hidden text salting” to bypass spam filters and evade detection.
This method, which saw a surge in usage during the latter half of 2024, poses a significant threat to organizations relying on traditional email defense mechanisms.
Hidden text salting, also referred to as “poisoning,” is a deceptively simple yet effective technique that leverages features of Hypertext Markup Language (HTML) and Cascading Style Sheets (CSS) to embed non-visible elements within the source code of emails.
Besides this, security experts at Cisco Talos discovered that these hidden elements are designed to confuse email parsers, spam filters, and detection engines that rely on keywords, while remaining invisible to the recipient when the email is rendered in their client.
Are you from SOC/DFIR Teams? - Analyse Malware Files & Links with ANY.RUN Sandox -> Try for Free
Attackers employ various methods to implement hidden text salting:-
This technique has proven effective in multiple ways. By inserting hidden characters between the letters of well-known brand names, attackers can evade filters designed to detect impersonation attempts.
Hidden text in different languages can also confuse language detection systems, as seen when Microsoft’s Exchange Online Protection (EOP) misclassified an English email as French due to concealed French text.
Additionally, the insertion of irrelevant content disrupts keyword-based filters, making it harder to identify suspicious phrases commonly associated with phishing attempts.
Traditional security measures struggle to counter hidden text salting effectively. Tools relying on automated keyword detection, brand name recognition, or standard language identification are particularly vulnerable to this technique.
The simplicity and versatility of hidden text salting make it a formidable challenge for email security providers.
To combat this emerging threat, security experts recommend:-
Security researchers at Fortinet's FortiGuard Labs have uncovered a sophisticated phishing campaign that uses weaponized…
British retail giant Marks & Spencer (M&S) has confirmed it is dealing with a significant…
In the face of relentless cyber threats and an ever-expanding digital attack surface, security leaders…
A sophisticated backdoor targeting various large Russian organizations across government, finance, and industrial sectors has…
In an era where cyber threats evolve faster than defense mechanisms, Chief Information Security Officers…
Zyxel Networks has released critical security patches to address two high-severity vulnerabilities in its USG…