
Device Code Phishing: MFA Bypass at Scale
This article describes real-world “device code phishing” campaigns where victims are tricked into approving an OAuth device login, granting attackers access…
Barracuda reports seeing more than one million retail-themed phishing emails since April that use “text salting,” where attackers hide large amounts of harmless text inside the message to trick automated email security tools. The victim sees a normal-looking urgent lure (like expiring rewards points), while hidden HTML/CSS content changes how some detection engines score the email. The campaign also uses authenticated-looking sending infrastructure (e.g., DKIM) and multiple hiding techniques to improve delivery.
Barracuda identified more than one million retail-themed phishing emails since April built around a technique called text salting. Recipients see a normal-looking urgent message, often claiming that rewards points, loyalty benefits, or a gift card are about to expire and encouraging immediate action. Behind that visible lure, the email's HTML/CSS contains large blocks of unrelated, benign-looking text that is hidden from the reader but present in the underlying code.
A related variant uses a technique called Zero Font, which inserts random hidden words directly inside a recognizable phishing phrase and sets the inserted text to a font size of zero. For example, the underlying HTML may read "Your pass [hidden text] word expired," while the recipient only sees "Your password expired." The campaign also relies on trusted infrastructure, authenticated domains, hidden HTML content, and CSS concealment techniques to improve delivery and reduce suspicion.
These emails work because the two layers of content serve different purposes. The visible layer is a simple, believable, urgent lure tied to something many people actually have, like rewards points or a gift card. The hidden layer is designed purely to manipulate how automated detection engines classify the message. Because some security tools scan the raw HTML or source code rather than what the user actually sees, the extra hidden text or invisible inserted words can throw off pattern-matching and signature-based detection, letting messages that would otherwise be flagged slip through to the inbox. Authenticated-looking sending infrastructure, including DKIM configured on lookalike or compromised domains, adds another layer of apparent legitimacy.
Employees, especially in customer support and sales roles that regularly handle retail-related email, should verify urgent expiration claims through a separate, trusted channel, such as typing the retailer's URL directly rather than clicking an embedded link. For password-reset or login requests, use a known bookmark or official portal instead of following a link in the email. Security and IT/identity teams should ensure email defenses analyze the message as it actually renders for the recipient, not just the raw HTML or source code, since that is where hidden content like text salting and Zero Font is designed to operate undetected.
Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.
Text salting is a technique where attackers hide large blocks of harmless-looking text inside a phishing email's HTML/CSS to change how automated detection tools score the message, while the visible message the user sees stays the same.
Zero Font is a technique that embeds random hidden words inside recognizable phishing phrases and sets that inserted text to a font size of zero, so it is invisible to the recipient but can confuse signature-based detection scanning the raw HTML.
Barracuda identified more than one million retail-themed phishing emails since April that used text salting.
Treat urgent messages about expiring rewards points, loyalty benefits, or gift cards as suspicious, and verify password-reset or login requests through a known bookmark or official portal rather than an embedded link.
You get an email: “Your rewards points are about to expire, act now.” It looks totally normal… and it passed all our filters. Behind that one line, the HTML is stuffed with hidden junk text, “text salting,” plus tricks like Zero Font, so AI email filters think it’s harmless while you just see an urgent rewards offer. Barracuda’s already seen over a million of these retail-themed emails since April, some even using authenticated-looking domains so DKIM passes. The only real tell? That “expiring rewards” or “password expired” panic, out of nowhere. If an email says rewards or a password are about to expire, don’t click the email. Type the retailer or account URL yourself and check from there.

This article describes real-world “device code phishing” campaigns where victims are tricked into approving an OAuth device login, granting attackers access…

Researchers observed LogoKit phishing campaigns that create a unique fake login page for each recipient in real time. The kit pulls a live screenshot of the…

A Japanese industrial manufacturer was targeted by the SilverFox group using an invoice-themed phishing email that kicked off a multi-stage malware chain. The…

A legal-sector threat intel report says adversary-in-the-middle (AiTM) phishing is now the most common way attackers gain initial access to law firms, because…

This bulletin describes multiple real-world social engineering campaigns where attackers trick people into trusting a familiar screen, like a search result…

Attackers sent emails that looked like Microsoft Teams/HR notifications and pushed users through Microsoft’s real sign-in and OAuth consent screens. When…