Hackers Use Text Salting to Evade AI Email Defenses
Email-security providers increasingly rely on large language models and machine learning to assess wording, context and intent in suspected phishing messages. Barracuda said attackers are reviving “text salting,” a long-used obfuscation technique, to exploit how those newer defenses weigh malicious signals. The tactic is significant because generative AI can automate the creation of convincing filler at scale, lowering the cost of campaigns designed to evade automated screening.
Barracuda recently found that hackers were using generative AI to produce large volumes of harmless-looking text and insert it into phishing emails. The added material dilutes the share of malicious keywords and suspicious phrases, potentially prompting LLM- and machine-learning-based tools to classify the messages as legitimate. The disclosed information did not specify an exact discovery date, the number of organizations affected or any financial losses tied to the technique.
All Coverage
1 original reportsThe Backstory
The history behind this eventNo historical echoes for this signal
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.