Analysis Surfaces Increased Usage of LLMs to Craft BEC Attacks
研究显示,在2022年2月至2025年4月期间的恶意邮件中,14%的商业电邮诈骗(BEC)攻击和51%的垃圾邮件由大型语言模型生成。网络犯罪分子利用AI优化邮件内容和英语表达,并测试不同措辞以提高攻击成功率。生成的邮件通常更正式且语法正确,但保持紧迫感。随着深度伪造技术的发展,未来大多数BEC攻击可能由LLM生成。网络安全团队需依赖元数据工具阻止此类攻击进入收件箱。 2025-7-3 11:30:29 Author: securityboulevard.com(查看原文) 阅读量:18 收藏

A Barracuda Networks analysis of unsolicited and malicious emails sent between February 2022 to April 2025 indicates 14% of the business email compromise (BEC) attacks identified were similarly created using a large language model (LLM).

Conducted in collaboration with a group of researchers from Columbia University and the University of Chicago, the analysis also finds that just over half (51%) of all the spam messages identified were written using an LLM.

Asaf Cidon, an associate professor at Columbia University, said in addition to simply increasing productivity, it appears cyberattackers are also leveraging generative AI to more rapidly create variants of these attacks that they hope will be more difficult to detect.

Techstrong Gang Youtube

AWS Hub

Cybercriminals also appear to be using AI to refine their emails and possibly their English rather than to change the tactics of their attacks. They are also testing variations of wording to see which are more effective in bypassing defenses and encouraging more targets to click links in much the same way A/B testing is conducted by marketers, the report finds.

The analysis also shows that while the emails generated using LLMs tend to be more formal and grammatically correct, they typically convey the same level of urgency generally associated with BEC attacks.

As a result, it is becoming more difficult for end users to detect these attacks, an issue that is likely to be further exacerbated with the rise of deepfakes that make use of AI to, for example, create audio files that impersonate executives, said Cidon. In fact, it won’t be long before most BEC attacks are crafted using LLMs, he added.

As such, cybersecurity teams will increasingly need to depend on tools and platforms that use metadata to thwart these attacks before they find their way into an inbox by identifying the domain used to send these messages, he added. While cybercriminals are getting more adept at creating new domains and websites to launch their attacks, advances in AI are also making it easier for cybersecurity defenders to identify them, he noted.

In effect, organizations of all sizes are now caught up in an AI cybersecurity arms race. Cybercriminals are clearly becoming more adept at using LLMs to create more attacks than ever. As the cost of crafting these attacks continues to drop to near zero, cybercriminals can afford to craft more of them simply because a few successful attacks can justify much of the effort, noted Cidon. Every malicious email that makes it into an inbox simply increases the chances one of those attacks will succeed, he added.

It’s not clear to what degree AI is changing the economics of cybersecurity for attackers and defenders, but the level of scale at which the battle is being fought is fundamentally changing. The only issue that remains to be seen now is to what degree some organizations will soon find themselves overwhelmed by these attacks simply because they, either out of ignorance or lack of budget, were unable to adjust to this new reality.

Recent Articles By Author


文章来源: https://securityboulevard.com/2025/07/analysis-surfaces-increased-usage-of-llms-to-craft-bec-attacks/?utm_source=rss&utm_medium=rss&utm_campaign=analysis-surfaces-increased-usage-of-llms-to-craft-bec-attacks
如有侵权请联系:admin#unsafe.sh