"Comment stuffing" in an HTML phishing attachment as a mechanism for evading AI-based detection?, (Fri, Jul 10th)

2026-07-10T13:23:47Z3b91df81aa248fb4be96a085c16b20b8e79b11c83b8812cfab6269be387f56de
ai-evasionattachment-sandboxingcomment-stuffingdetection-evasionemail-attachmentevasionhtml-commentmail-filteringphishingsans_isc

What happened

SANS ISC highlights a phishing sample that uses “comment stuffing” inside HTML attachments to evade AI- and heuristic-based detectors. Attackers inject large amounts of HTML comments and benign-looking noise to alter tokenization/feature extraction, obscure malicious text and links, and frustrate simple parsers and ML models. Impact is increased likelihood of content-based detection bypass and false negatives for mail filters and attachment scanners. Recommended mitigations include normalizing/stripping HTML comments before analysis, rendering and analyzing the DOM (not just raw source), doing

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
sans_isc_diary
Record identifier
3b91df81aa248fb4be96a085c16b20b8e79b11c83b8812cfab6269be387f56de
Enrichment time
2026-07-10T13:23:47Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.