AI phishing

Are the bad guys using AI?

They might! AI tools like ChatGPT or DALL-E-2 are currently widely tested out on the internet – both for the good as well as for the bad.

From my point of view, we are at the very beginning of an interesting development, which will unfold over the next couple of years. AI will play an increasing role in both attacking as well as protecting systems.

I’ve included a very simple example in this post – I’ve used ChatGPT to create an e-mail template an attacker could use within a phishing attack. Pretty impressive – especially if you compare it to the phishing mails loaded with typos and grammatically wrong sentences we’ve been used to some years ago.

Be aware – and always try to be one step ahead of the attacker!

Image of a AI generated phishing mail template.
The image shows an email notification informing customers that their login credentials have expired and they need to re-verify their credentials to ensure the security of their account. The email includes a link to a re-verification page and instructions on how to complete the process. It also offers an apology for any inconvenience caused and emphasizes the importance of account security. The email concludes with contact information for customer support in case of questions or concerns and expresses gratitude for choosing their company. The email is signed by the company, represented by the placeholder "[Your Company Name]."

Similar Posts

  • ISO 42001 Practitioner certification

    This month I’ve earned the ISO/IEC 42001:2023. Artificial intelligence management system practitioner certification of rigcert.education. As AI systems become widely integrated into the business world, securely managing them is increasingly critical. How can organizations ensure the reliability of AI outputs, protect company data from loss, and maintain system availability? These topics—and many others—are addressed by…

  • AI in the rail sector

    We are already seeing real-world applications of artificial intelligence in the rail sector. Deutsche Bahn is using artificial intelligence to reduce delays on its network. My prediction: This is just the beginning of ML/AI applications in our sector. We will see machine learning and AI algorithms becoming more and more widespread in the coming years….

  • 2FA phishing

    A new hashtag#attack technique on the rise: 2FA phishing.Learn how it works: How do attackers try to get around multi-factor authentication? https://www.microsoft.com/en-us/security/blog/2022/07/12/from-cookie-theft-to-bec-attackers-use-aitm-phishing-sites-as-entry-point-to-further-financial-fraud

  • CVE-2024-3094: xz-utils backdoor

    The newly discovered xz-utils backdoor, which was published yesterday (NVD – CVE-2024-3094 (nist.gov)) also affects one of the Linux distributions most used by penetration testers: Kali Linux. ❗Make sure, that you are updating your Kali installations as fast as possible, especially when you updated them before in the time frame between 26.03.2024 and 29.03.2024. 💡For…

  • AI tracking

    AI can track the time you spend on your phone during work. The post below shows an interesting demonstration of the technical capabilities. From my point of view, these kind of AI applications will be and should be a focus of a broad public discussion in the near future. AI applications will offer great opportunities,…