
Summary
Detects inbound HTML messages that attempt to hide content with CSS-driven concealment (e.g., extreme negative z-index, zero-width/zero-height elements) when used in conjunction with <option> elements carrying label attributes. The rule looks for HTML patterns where option nodes contain nested table or article elements and uses an ML-based natural language classifier on the inner text to identify credential-theft intent with non-low confidence. This pattern represents a text-salting evasion tactic designed to bypass content-analysis engines and facilitate credential phishing. Alerts indicate potential hidden-content phishing, with evasion and brand impersonation cues.
Categories
- Web
- Application
Data Sources
- Web Credential
Created: 2026-09-02