Goto

Collaborating Authors

 phishing


AI Rewrites the Rules Of Phishing, Cybercrime

Communications of the ACM

It used to be just a sci-fi nightmare scenario, but today, AI phishing is real, and it's costing companies millions. We've already touched upon this one, but the Hong Kong phishing scam that targeted an employee at Arup deserves a deeper dive. The employee was tricked by deepfake versions of her CFO and colleagues into transferring HK 200 million across 15 transactions. The case has been widely reported and confirmed by the Hong Kong police. Every face and voice was AI-generated.


LLM-Powered Intent-Based Categorization of Phishing Emails

arXiv.org Artificial Intelligence

--Phishing attacks remain a significant threat to modern cybersecurity, as they successfully deceive both humans and the defense mechanisms intended to protect them. Traditional detection systems primarily focus on email metadata that users cannot see in their inboxes. Additionally, these systems struggle with phishing emails, which experienced users can often identify empirically by the text alone. This paper investigates the practical potential of Large Language Models (LLMs) to detect these emails by focusing on their intent. In addition to the binary classification of phishing emails, the paper introduces an intent-type taxonomy, which is operationalized by the LLMs to classify emails into distinct categories and, therefore, generate actionable threat information. T o facilitate our work, we have curated publicly available datasets into a custom dataset containing a mix of legitimate and phishing emails. Our results demonstrate that existing LLMs are capable of detecting and categorizing phishing emails, underscoring their potential in this domain.


Detecting Voice Phishing with Precision: Fine-Tuning Small Language Models

arXiv.org Artificial Intelligence

We develop a voice phishing (VP) detector by fine-tuning Llama3, a representative open-source, small language model (LM). In the prompt, we provide carefully-designed VP evaluation criteria and apply the Chain-of-Thought (CoT) technique. To evaluate the robustness of LMs and highlight differences in their performance, we construct an adversarial test dataset that places the models under challenging conditions. Moreover, to address the lack of VP transcripts, we create transcripts by referencing existing or new types of VP techniques. We compare cases where evaluation criteria are included, the CoT technique is applied, or both are used together. In the experiment, our results show that the Llama3-8B model, fine-tuned with a dataset that includes a prompt with VP evaluation criteria, yields the best performance among small LMs and is comparable to that of a GPT-4-based VP detector. These findings indicate that incorporating human expert knowledge into the prompt is more effective than using the CoT technique for small LMs in VP detection.


Assessing AI vs Human-Authored Spear Phishing SMS Attacks: An Empirical Study Using the TRAPD Method

arXiv.org Artificial Intelligence

This paper explores the rising concern of utilizing Large Language Models (LLMs) in spear phishing message generation, and their performance compared to human-authored counterparts. Our pilot study compares the effectiveness of smishing (SMS phishing) messages created by GPT-4 and human authors, which have been personalized to willing targets. The targets assessed the messages in a modified ranked-order experiment using a novel methodology we call TRAPD (Threshold Ranking Approach for Personalized Deception). Specifically, targets provide personal information (job title and location, hobby, item purchased online), spear smishing messages are created using this information by humans and GPT-4, targets are invited back to rank-order 12 messages from most to least convincing (and identify which they would click on), and then asked questions about why they ranked messages the way they did. They also guess which messages are created by an LLM and their reasoning. Results from 25 targets show that LLM-generated messages are most often perceived as more convincing than those authored by humans, with messages related to jobs being the most convincing. We characterize different criteria used when assessing the authenticity of messages including word choice, style, and personal relevance. Results also show that targets were unable to identify whether the messages was AI-generated or human-authored and struggled to identify criteria to use in order to make this distinction. This study aims to highlight the urgent need for further research and improved countermeasures against personalized AI-enabled social engineering attacks.


COPS: A Compact On-device Pipeline for real-time Smishing detection

arXiv.org Artificial Intelligence

Smartphones have become indispensable in our daily lives and can do almost everything, from communication to online shopping. However, with the increased usage, cybercrime aimed at mobile devices is rocketing. Smishing attacks, in particular, have observed a significant upsurge in recent years. This problem is further exacerbated by the perpetrator creating new deceptive websites daily, with an average life cycle of under 15 hours. This renders the standard practice of keeping a database of malicious URLs ineffective. To this end, we propose a novel on-device pipeline: COPS that intelligently identifies features of fraudulent messages and URLs to alert the user in real-time. COPS is a lightweight pipeline with a detection module based on the Disentangled Variational Autoencoder of size 3.46MB for smishing and URL phishing detection, and we benchmark it on open datasets. We achieve an accuracy of 98.15% and 99.5%, respectively, for both tasks, with a false negative and false positive rate of a mere 0.037 and 0.015, outperforming previous works with the added advantage of ensuring real-time alerts on resource-constrained devices.


Large Language Model Lateral Spear Phishing: A Comparative Study in Large-Scale Organizational Settings

arXiv.org Artificial Intelligence

The critical threat of phishing emails has been further exacerbated by the potential of LLMs to generate highly targeted, personalized, and automated spear phishing attacks. Two critical problems concerning LLM-facilitated phishing require further investigation: 1) Existing studies on lateral phishing lack specific examination of LLM integration for large-scale attacks targeting the entire organization, and 2) Current anti-phishing infrastructure, despite its extensive development, lacks the capability to prevent LLM-generated attacks, potentially impacting both employees and IT security incident management. However, the execution of such investigative studies necessitates a real-world environment, one that functions during regular business operations and mirrors the complexity of a large organizational infrastructure. This setting must also offer the flexibility required to facilitate a diverse array of experimental conditions, particularly the incorporation of phishing emails crafted by LLMs. This study is a pioneering exploration into the use of Large Language Models (LLMs) for the creation of targeted lateral phishing emails, targeting a large tier 1 university's operation and workforce of approximately 9,000 individuals over an 11-month period. It also evaluates the capability of email filtering infrastructure to detect such LLM-generated phishing attempts, providing insights into their effectiveness and identifying potential areas for improvement. Based on our findings, we propose machine learning-based detection techniques for such emails to detect LLM-generated phishing emails that were missed by the existing infrastructure, with an F1-score of 98.96.


How to plot a regplot using the seaborn Python library? - The Security Buddy

#artificialintelligence

We can use a regression plot or regplot to plot data and a linear regression model fit. For example, let's say we are reading the tips dataset. The dataset contains various information, such as total bill, tip amount, etc. Let's say we want to see the relationship between the total bill and the tip amount. For that purpose, we can plot a regression plot. We can use the following Python code to plot a regression plot between the total bill and the tip amount.


Deepfake: A new formula for Phishing?

#artificialintelligence

Phishing is the activity of a site appearing as another, and trying to deceive the user of the site into mistaking the attacker's site as the one the user wants to use. This has caused an infinite number of fraudulent transactions and other criminal activities. Now think what happens if the person that you think you are looking at in an online video, is not the same person at all. It is a digitally rendered copy of the person, however, this time it's not just a still, it's a moving, talking video of the person with features almost indistinguishable from the person that it is supposed to be. Read along to find more on what I'm talking about.


AI Is A Double-Edged Sword In Phishing

#artificialintelligence

Every day, on average, 56 million phishing emails are sent, and it takes just 82 seconds for a person to be victimised by such attacks. Phishing is one of the oldest yet effective forms of a cybersecurity threat. Over time it has graduated from scamming emails from a Nigerian prince to more sophisticated and sly techniques, such as Distributed Spam Distraction, polymorphic attacks, and visual similarity attack. Artificial intelligence has played a great role in thwarting attacks of such nature. Let us look at a few such examples.


The DNC's Technology Chief is Phishing His Staff. Good.

WIRED

If you are among the millions of Americans concerned about cybersecurity at the Democratic National Committee--and how could you not be?--then the home of the party's tech braintrust might not give you much hope. The tiny, charmless office, with "DNC Tech" scribbled in dry-erase marker on the door, contains one desk and two computer monitors. Nearby, an overturned couch pokes out from an elevator shaft, a leftover from the widespread departures that followed Hillary Clinton's defeat. And that, of course, came after intruders, believed to be tied to Russia, hacked into the DNC's computers. If the office itself seems lacking, the resume of its newish occupant is anything but.