Uncategorized

Phishing Emails Generated by ChatGPT & Human Models Gained 81% Click Rates

Explosive growth in natural language processing, fueled by advances like GPT-4 and Claude, empowers human-like text generation and superhuman linguistic abilities.

In just one year, the model size and performance surged significantly, as the current scenario shows that:-

  • LLMs surpass 100 billion parameters
  • GPT-4 surpasses 1.8 trillion parameters (Not confirmed, rumored)

Security researchers, including Fredrik Heiding, recently demonstrated at Black Hat USA 2023 that large language models can create functional phishing emails, slightly less convincing than manual designs.

Phishing Emails Generated by ChatGPT

The team, including security expert Bruce Schneier, Avant Research Group’s Arun Vishwanath, and MIT’s Jeremy Bernstein, tested 4 LLMs that are commercial to perform the phishing experiments on Harvard students.

The 4 commercial LLMs that are used by the researchers are:-

  • OpenAI’s ChatGPT
  • Google’s Bard
  • Anthropic’s Claude
  • ChatLlama
Four common LLMs (Source – BlackHat)

In the test, 112 students received phishing emails with Starbucks gift card offers. Despite strong safeguards, LLMs can still generate marketing content, potentially repurposed for attacks.

Researchers tasked ChatGPT to craft a 150-word email offering a $25 Starbucks gift card for Harvard students. While they compared it with V-Triad, a non-AI model that is specialized in convincing phishing emails and was developed by Vishwanath.

Control Group Email (Source – BlackHat)
ChatGPT Email (Source – BlackHat)
V-Triad Email (Source – BlackHat)
V-Triad & ChatGPT Combo Email (Source – BlackHat)

Experiment by Researchers

The experiment involved 3 phases, and here below, we have mentioned all the phases:-

  • Phase 1 gathered student and university info.
  • Phase 2 devised emails under a control group of ChatGPT, V-Triad, ChatGPT/V-Triad combo.
  • Phase 3 sent emails in 10-batch cycles from 10:30 a.m. to 2:30 p.m.

Here below we have mentioned the respective results of each model:-

  • V-Triad email performed best with a 70% click rate.
  • V-Triad/ChatGPT combo with a 50% click rate.
  • ChatGPT email had a lower rate of 30%.
  • The control group was last with a 20% click rate.

ChatGPT didn’t mention Harvard in the first test, leading to a lower rate. ChatGPT improved to 50% clicks in a different test version, while the V-Triad/ChatGPT combo achieved a score of 80%.

In the next phase, ChatGPT, Bard, Claude, and ChatLlama assessed the intent of Starbucks and legit marketing emails. LLMs evaluated human or AI composition, detected suspicious elements, and gave response advice.

Researchers highlighted the effectiveness of the LLMs in spotting suspicious emails, stressing their potential for broad use without security data training. That’s why cybersecurity analysts affirmed that the LLMs are powerful tools.

Keep informed about the latest Cyber Security News by following us on GoogleNewsLinkedinTwitter, and Facebook.

Guru Baran

Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

3 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

3 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

4 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

4 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

4 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

6 hours ago