Phishing, AI/ML

GenAI could power dynamic, personalized phishing websites, Unit 42 warns

Per Tech Radar, security researchers are warning that generative AI (GenAI) could enable the creation of dynamic and personalized phishing websites, posing a new threat to cybersecurity.

Palo Alto Networks' Unit 42 has detailed a method where victims are directed to a seemingly harmless webpage. This page then prompts a legitimate large language model (LLM) API, which generates unique JavaScript code tailored for each user. This code is executed in the victim's browser, assembling a personalized phishing page without any static malicious code for traditional detection methods to intercept.

While the method is currently a proof-of-concept, the building blocks are already being utilized in various cybercrime activities, with LLMs increasingly used to generate obfuscated JavaScript and aid in malware campaigns.

Source: Tech Radar

An In-Depth Guide to AI

Get essential knowledge and practical strategies to use AI to better your security program.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds