Accessibility links
  • Skip to main content
News Icon NEWS FILTER
All News Security Education Videos Scams & Phishing Your Security Mobile Security Identity Theft Corporate Security
Search Icon SEARCH
 

Email Icon SUBSCRIBE TO WEEKLY NEWSLETTER
AI ChatGPT And PaaS Merge, Further Weaponizing Email Phishing Campaigns
Facebook   X   LinkedIn   Email

AI ChatGPT And PaaS Merge, Further Weaponizing Email Phishing Campaigns

March 27, 2024

Hold on to your login credentials! A recent look at email phishing campaigns uncovered a 61% spike in attacks over the second half of last year. However, security pros find AI (artificial intelligence) is now accelerating these campaigns, and the number of attacks will significantly increase going forward. With the release of the AI ChatGPT platform coupled with PaaS (phishing-as-a-service) kit upgrades, email phishing is slated to be more pervasive and destructive than ever before.

ChatGPT, an AI platform created by OpenAI and released late last year, uses chatbots to create interactive user experiences. And now, this AI tool is fast becoming a phisher’s best friend. The meteoric rise in popularity of ChatGPT, along with improvements to easily available PaaS kits, spells trouble for enterprise security. Successful phishing attacks open the door to further crimes like ransomware, account takeovers (ATOs), identity theft, and espionage, among others.

Phishing by the Numbers

As it is, email phishing leads to over 90% of corporate security breaches, and more than 60% of SMBs (small-to-medium-size businesses) close their doors within months of a phishing attack. In the fourth quarter of last year alone, Vade email security found 58.9 million emails carried malware, an existential threat to organizations everywhere.

Vade also found monthly volumes for phishing were 62.3 million in October of last year, and 47 million in November, nothing too unusual. But in December, a crazy-popular time for holiday and end-of-year phishing scams, they report a jump to 169 million, finalizing a month-over-month total increase of 260%.

ChatGPT supports countless personal and business tasks, particularly on massive scales. Writing emails and other communications barely scratch the surface of what ChatGPT can do, but using it for email phishing campaigns is where cybercriminals are focusing their efforts.

In the Crosshairs

Vade’s research revealed the top two phishing targets in the second half of last year are also the two most used productivity suites, Microsoft 365 and Google Workspace. Targeting productivity apps commonly used by corporations casts a wide net for success. Exactly who and what these now accelerated phishing attacks target next is a question mark.

It’s important to remember that anyone, no matter their skill level, can become a phishing threat. Creating enhanced PaaS phishing kits with ChatGPT means new phishing threats are rapidly coming to fruition. According to Vade, “Hackers can weaponize ChatGPT to produce sophisticated phishing kits efficiently by using commands that empower the AI tool to write phishing emails and malicious code in seconds…that’s already become notorious for its cybersecurity implications…”

Always be on the lookout for phishing. The top give away is that you aren't expecting the link or attachment and/or that the message makes you feel like you need to do something in a hurry.

While phishing might have been difficult to detect before, it is likely to become even more challenging going forward. We will have to wait and see how much.


Phony Voicemail Links Steal Employee Credentials From Office 365 And Outlook Users

Scams & Phishing

Phony Voicemail Links Steal Employee Credentials From Office 365 And Outlook Users

Most of us know phishing emails and fake texts are a hacker’s calling card for stealing valuable PII. But recently, researchers at Zscaler cloud security sounded the alarm about an unusual malware campaign using voicemail-themed email phishing as the primary hook for cyberattacks. It’s only after Zscaler fell victim to this campaign that the company felt compelled to study it further. Zscaler finds this cybercrime targets employees in the U.S. using Microsoft Office 365 and the Outlook email service. READ FULL STORY

Top Phishing Scams Continue To Improve And Grow

Education

Top Phishing Scams Continue To Improve And Grow

Much to our dismay, cybercrooks keep finding ways to better the phishing tools they have and find other ways to include new and sneakier methods of thievery. Organizations and individuals are targets and money, identities, credentials, and more are stolen from both every day. Even cyber-savvy users can get caught in phishing scams if they don’t pay close attention to the signs and signals that something isn’t quite right. Reviewing the most pervasive phishing scams is always recommended. READ FULL STORY

Malware Downloads From Harmless Word Document

Scams & Phishing

Malware Downloads From Harmless Word Document

You have heard it over and over and likely, your reaction is “Yes, I know. Don’t enable macros in Microsoft documents or spreadsheets.” Well, don’t plug your ears or turn away, but you’re about to hear it again…only for a new reason. Some who have less than great intentions have figured out a way to get those macros enabled using a seemingly harmless Microsoft Word document (.doc). So now, even if you have them disabled by default, someone has found a way to get those enabled for you; like it or not. READ FULL STORY

Are You Getting Smished? How To Tell And How To Avoid It

Mobile Security

Are You Getting Smished? How To Tell And How To Avoid It

It doesn’t take much to be a smishing victim when just a text message does the trick. A member of the email phishing and voice (vishing) family of criminal scams, replying to a smishing text can be all that’s needed to begin a successful scam. Knowing how smishing works and the tell-tale signs of these scams can help keep you from being the next smishing victim. Using pressure, fear, curiosity, trust, winning a contest, and other tactics increase their chances of reeling you in. But what do you do when a text has only one word? READ FULL STORY








Close
Fraud News & Alerts!

Keep up with the latest cyber security news through our weekly Fraud News & Alerts updates. Each week you will receive an email containing the latest cyber security news, tips and breach notifications.



You're all set!

You will receive your first official security update email within the next week.

A welcome email has also just been sent to you. If you do not receive this email within the next few minutes, please check your Junk box or spam filter to confirm our emails are not being blocked.


 
Help  
Enter any word or words you like.        

The email newsletter will arrive from news@stickleyonsecurity.com


Loading
Please wait...