US23-Heiding-Devicing-and-Detecting-Phishing.pdf
ID: 93afe77c-b1b9-45fe-80c1-1bc2f5230ae1
STIX ID: report--93afe77c-b1b9-45fe-80c1-1bc2f5230ae1
Threat Score
60/100
Uploaded: 2026-08-11
Published Date: 2023-08-08
Last Modified Date: 2023-08-08
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
This Black Hat USA 2023 presentation analyzes the risks and capabilities of using large language models (LLMs) to craft and automate phishing attacks. The researchers compare LLM-generated emails, a human-centered V-Triad model, and combinations thereof in an experiment with Harvard-affiliated participants, reporting click-through rates as high as ~65% for V-Triad messages and elevated success when using targeted, credibility-focused templates. The talk outlines a four-phase automation workflow (collect background information, create phishing emails, send emails, analyze results), gives example phishing templates, evaluates intent/AI-detection by various models, and concludes with both warnings about easier-to-launch sophisticated phishing and recommendations to leverage LLMs defensively for training and detection.
