Attackers are increasingly leveraging cascading style sheets (CSS) to insert hidden text and irrelevant content into emails, a tactic known as hidden text salting, to evade detection by email security solutions. Cisco Talos has been monitoring this trend for over a year, observing a significant rise in the use of CSS-based hidden content in both spam and malicious emails. The technique involves embedding random characters, nonsense paragraphs, and hidden comments within various parts of an email, such as the preheader, header, attachments, and body. These elements are manipulated using CSS properties that control text visibility and sizing, making the added content invisible to the recipient but confusing to automated detection systems. This method is particularly effective at bypassing both traditional spam filters and advanced machine learning-based email defenses, as it introduces noise that can disrupt keyword-based and pattern-matching algorithms. Cisco Talos has reported on this tactic multiple times throughout 2025, noting a steady increase in its adoption by threat actors. The abuse of CSS for hidden text salting is not limited to a single campaign but is widespread across various email threats, making it a substantial challenge for enterprise security teams. Researchers highlight that while CSS is a legitimate tool for enhancing email appearance and branding, its misuse for content concealment is now a common feature in malicious campaigns. The prevalence of hidden text salting in spam and phishing emails far exceeds its occurrence in legitimate communications, underscoring its role as a deliberate evasion strategy. Security experts warn that this technique can also impact the effectiveness of large language model (LLM)-based defense solutions, which may be particularly susceptible to poisoned or noisy input. The ongoing evolution of this tactic demonstrates the adaptability of threat actors in circumventing security controls. Cisco Talos has shared key findings with the security community to raise awareness and encourage the development of more robust detection mechanisms. The research emphasizes the need for email security solutions to account for hidden and obfuscated content, not just visible text. Organizations are advised to review their email filtering rules and consider enhancements that can detect and neutralize hidden text salting. The continued monitoring and reporting by Cisco Talos provide valuable intelligence for defenders seeking to stay ahead of these evolving email-based threats.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
1 event from the most recent confirmed update back to the earliest known activity.
On 2025-10-07, Cisco Talos published research describing attackers' abuse of CSS to hide salted text in spam messages, and Dark Reading reported on the same technique the same day. The references indicate public disclosure of the tactic but do not provide earlier dated events such as a first observed campaign, victim disclosure, or remediation milestone.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.