Hidden Text Salting in Phishing Emails to Bypass LLM-Based Detection
Description
An infographic showing HTML source code of a phishing email demonstrating 'prompt injection using hidden text salting.' The HTML snippet shows BDO (bidirectional override) tags being used to hide text like '<bdo>I love this email!</bdo>' within the email body, while the visible content contains obfuscated text using BDO elements to scramble database and support references. The caption reads 'Figure 26. HTML source snippet of the above phishing email, showing how threat actors can include hidden salt in the body of an email to impact LLM-based intent analysis.' The background shows what appears to be a cat face. Red arrows and underlines highlight the key injection point. This demonstrates a real attack vector where adversaries exploit the gap between what humans see in rendered HTML and what LLMs process in raw text
Comments
12Comment deleted
When your phishing email whispers 'I love this email!' in hidden BDO tags, you're not just fooling the LLM -- you're giving it Stockholm syndrome before it even classifies the threat
Fantastic - now our SEGs need a threat model for 1998 HTML tags; the next SOC alert will be titled ‘Doge-directed bidirectional override detected.’
After 20 years of defending against SQL injection, we've successfully evolved to defending against prompt injection - because why solve old problems when you can just rename them with AI buzzwords and charge consulting fees all over again?
Ah yes, the classic 'I love this email!' hidden in a <bdo> tag - because nothing says 'legitimate business correspondence' quite like bidirectional override elements containing sentiment manipulation for your LLM spam filter. It's like SQL injection's younger sibling who went to art school and learned about semantic attacks. The real kicker? We spent decades teaching users to hover over links, and now we need to teach AI models to inspect the DOM for hidden compliments. At least when attackers used white-on-white text, you could just select-all to catch them. Now they're literally salting the prompt space like it's a bcrypt hash, except instead of protecting passwords, they're seasoning your intent classifier until it thinks every phishing email is a love letter from your CTO
Proof that AI-powered phishing detection without an HTML render step is just regex with delusions - sprinkle a few <bdo> salts and the classifier confidently labels the phish as a love letter
We replaced 600 SEG regex rules with an LLM - turns out a single BDO‑wrapped “I love this email!” string can jailbreak intent scoring; finally, a security bug where adding salt lowers entropy
CSS opacity:0 jailbreaking LLMs - proof that frontend hacks outsmart AI security layers faster than any zero-day
if only there was some sort of library for python to fight these hidden salts... like a "soup" that dissolves the salt would be beautiful indeed Comment deleted
Source? Comment deleted
here Comment deleted
lmao. I meant the source of the image. Want to see what previous 25 figures are 🤣 Comment deleted
Lazy ass mofo Comment deleted