Scworld
Phishing Emails Use Obfuscation to Evade NLP Detection
Article Content
A new email obfuscation technique is being employed by malicious actors to bypass Natural Language Processing (NLP) email defenses. This method involves embedding typical phishing content at the beginning of emails, followed by a significant amount of unrelated benign content, often using over 100 line breaks to obscure the malicious intent. KnowBe4 analyzed 40 such emails and found that 63% utilized this obfuscation, with an average of 157 line breaks. The emails often included legitimate links and email signatures to further confuse recipients and security systems. Additionally, some emails contained randomized subject lines and attachment names, complicating mass deletion efforts by administrators. The obfuscation technique increases email length, potentially causing delays in scanning by security tools. Advanced AI-driven solutions and zero-trust email defenses may be more effective in detecting these threats.
Key Points: • Phishing emails now use obfuscation techniques to evade NLP detection. • 63% of analyzed emails employed over 100 line breaks to confuse scanners. • Advanced AI solutions and zero-trust approaches may better detect these threats.
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.