Everes

Turning the tables on Scammers: Why AI is the Key Ally

It’s commonplace to think that careless people are the ones who get scammed online. Not true. In fact, organizations and even governments fall prey to scammers who are increasingly getting more sophisticated in their ways. It was in the month of August 2022 that the City of Lexington realized that it had lost about $4 Million to an email fraud scheme. The theft involved three wire transfers to a private bank account, money that was originally intended to go to the non-profit community Action Council in Lexington. The attacker, in this case, impersonated an email account belonging to the local housing group associated with the city. Note that Lexington is not the only city to have suffered at the hands of scamsters. The city of Portland lost $1.4 Million and Peterborough, New Hampshire $ 2.3 Million. All these losses related to email fraud schemes. The list of such victims grows by the day. Email phishing schemes universally affect all types of companies, non-profit organizations, governments and private citizens.

Scamming Enters the New Age

New-age scammers are now relying on a super-intelligent ally. Enter AI, the latest tool that is now being used to generate and carry out extremely sophisticated email phishing attacks. This was amply demonstrated at one of the Black Hat and Defcon conferences, where a team of researchers used two sets of phishing emails. One was developed by the team, whereas the other was generated using AI. Both emails contained links that collected data to report the number of clicks. These emails were then sent to a sample of 200 recipients. When the click rates were analyzed, it was found that the recipients of the emails clicked the links in the AI-generated phishing emails by a wide margin in comparison to one that the researchers generated. Even though the tested sample in this experiment was relatively smaller and homogeneous, the study clearly showed that AI-generated content was far more potent in launching phishing and spear phishing campaigns.

Phishing emails crafted using AI and those generated by human agents have marked differences in sophistication. AI-generated phishing emails use machine learning algorithms to closely imitate the recipient’s behaviors and habits. This includes learning the subject’s usage of grammar and sentence construction, profession, situational context and interest to craft a message. Such sophisticated content proves extremely difficult to detect with traditional phishing defense mechanisms.

Hacked websites are a goldmine of data about an organization that can be harvested and organized by AI to launch a spear phishing attack targeted at a very specific context. A payment that is due or an event that is soon to happen can be leveraged to lure the victim into divulging personal or financial information. Voice cloning using AI can mimic a genuine voice with extremely high accuracy and can fool unsuspecting victims into falling prey to nefarious schemes.

A recent study revealed that threat actors are increasingly using zero hour attacks, of which spear phishing credential harvesting was the majority. Using previously failed attempts and by leveraging machine learning, they bombard organizations with a large volume of targeted phishing attacks increasing the likelihood of compromise. These phishing attacks contain link-based

attacks, attachments that are malicious and natural language threats.

"New-age scammers are now relying on a super-intelligent ally. Enter AI, the latest tool that is now being used to generate and carry out extremely sophisticated email phishing attacks"

Turning the Tables With the Same New Age Tools

However, there is hope; fire can be fought with fire. AI is now being increasingly used to detect phishing and spear phishing emails generated by AI itself. Machine learning algorithms can be trained using a large pool of normal emails contrasted with another large set of phishing emails to detect patterns and anomalies. Social graph analysis can be used to establish normal communication flows, email communication profiles to understand normal style and tone. Analysis of email structure helps understand technical aspects of an email that can be used to create a baseline for the machine learning algorithm to detect anomalies.

Content analysis can be done by AI to detect phishing emails. Using content such as greetings, sense of urgency, links and attachments and requests for sensitive information in emails, red flags can be raised, and threats detected. Natural language processing, which involves looking at the sender and subject names, email content, locations and company names, is also used by ML to detect a potential phishing attack. Convolutional Neural Network can detect manipulated images within the body of an email. Thus, the power of AI can be used for good to track and stop the bad guys in their tracks before they can do damage.

Note that improving machine learning to detect AI crafted phishing emails is a continuous process. These models can be improved continuously to detect evolving threats by training the ML algorithm. This feedback training makes these ML models efficient, which in turn helps ML-powered security defense mechanisms to become more accurate. Adopting an AI-based email security solution to thwart an AI-based phishing attack is the need of the hour!

The articles from these contributors are based on their personal expertise and viewpoints, and do not necessarily reflect the opinions of their employers or affiliated organizations.