Hackers Found A Terrifying Way To Blind AI Security Filters

Rohitshivani
5 Min Read
Cybercriminals are hiding massive amounts of invisible text inside emails to bypass AI-powered security gateways.

Artificial intelligence was supposed to be the ultimate shield against phishing attacks. Capable of reading context, analyzing sentiment, and spotting anomalies faster than any human, AI email scanners felt like a silver bullet. However, cybercriminals have discovered a devastatingly simple workaround.

By manipulating the visual structure of emails, attackers are successfully tricking some of the world’s most advanced security filters. Recent research from Barracuda Networks highlights a massive surge in retail-themed phishing campaigns that utilize a technique known as “text salting” to hide malicious intent in plain sight. If your organization relies strictly on automated source-code scanners, your inbox might already be compromised.

The Problem: How “Text Salting” Confuses Artificial Intelligence

To understand the threat, you have to understand how modern AI email security operates. When a Large Language Model (LLM) or automated gateway scans an incoming message, it reads the raw HTML source code to determine the email’s intent and risk level. It looks for urgent language, suspicious links, and common phishing trigger words like “expires,” “rewards,” or “password”.

Hackers counter this by using text salting—flooding the email’s code with vast amounts of unrelated, harmless text. To a human reader, the email looks like a standard retail gift card offer. But to the AI scanner reading the raw data, the email appears to be a long, innocent story or a set of project notes filled with positive, benign words like “puppy,” “training,” “book,” and “rhythm”.

Because the AI is not trained to know that this benign text is actually invisible to the user, the overwhelming volume of harmless words dilutes the malicious payload, causing the scanner to misclassify the phishing attempt as perfectly safe.

Real-World Examples: The Anatomy Of An Invisible Attack

Barracuda Networks tracked over one million of these sophisticated, retail-themed phishing attacks. To keep the salted text hidden from the human victims while leaving it fully legible to the AI, attackers layer multiple visual concealment tricks within the email’s code.

Here are the primary methods used to blind security systems:

Concealment TechniqueHow It WorksImpact on Security Scanners
Zero-Font SizingShrinks characters so they are entirely invisible to the human eye.AI reads the hidden text as normal context, diluting threat scores.
CSS Clipping & IndentationUses CSS commands to crop the viewing window or pushes text entirely off-screen.Scanners process paragraphs of unseen benign words without realizing they are hidden.
Color-MatchingBlends text directly into the email’s background color.Bypasses visual human detection while AI still parses the data.
HTML FragmentationSplits a trigger word into pieces (e.g., “pass[hidden-text]word”).Defeats exact-phrase signature matching used by traditional filters.

Advanced Topics: The Generative AI Threat Loop

Ironically, the same generative AI technology meant to protect us is making text salting exponentially worse. In the past, writing thousands of words of unique, benign text to bypass spam filters was incredibly time-consuming for hackers.

Today, attackers use LLMs to instantly generate endless variations of normal-sounding paragraphs at zero cost. This means every single phishing email sent in a campaign can feature entirely unique hidden text, completely breaking signature-based detection models that rely on identifying repeating patterns. A dangerous malicious link can now be effortlessly buried inside a massive, uniquely generated invisible story.

The Solution: Layered Defenses And Visual Rendering

Relying exclusively on keyword detection and raw text analysis is no longer sufficient. As text salting evolves, organizations must upgrade their email security architecture.

To combat visual manipulation, modern cybersecurity solutions must analyze emails exactly as the end-user sees them, rather than just reading the underlying source code. By utilizing optical character recognition (OCR) and advanced rendering techniques, security tools can compare the visible message against the raw HTML. If an AI detects a massive discrepancy between what the code says and what the human actually sees, the system can immediately flag the email as a sophisticated evasion attempt.

Ultimately, defeating these invisible threats requires a layered approach: combining structural analysis, sender reputation checks, visual rendering, and continuous employee awareness training.

Share This Article
if you'll give me a problem.. i'll find the Solution..
Follow:
Party All Night...