现代钓鱼邮件内容的大规模实证研究
A Large-Scale Empirical Study of Modern Phishing Email Content
浏览论文内容
中文总结 AI 辅助
本研究基于290万封真实钓鱼邮件的大规模语料,利用LLM流水线分析主题、行动号召和冒充三个维度,发现攻击手段多样化但响应方式趋同,且附件承担补充、替代或强化文本的三种角色,并揭示了发票主题钓鱼CTA的长期演变。
中文摘要 AI 辅助
钓鱼攻击仍然是对互联网用户最普遍的威胁之一,而电子邮件仍然是其主要的投递渠道。邮件内容正是钓鱼攻击的攻击面:它是受害者所阅读的内容,也是自动化防御系统所检查的对象。然而,现代钓鱼内容的构成却缺乏充分的测量。先前的工作已经表征了诸如主题、行动号召(CTA)和冒充等维度,但并未在大规模上进行,且由于语料库规模小或来源单一、使用词袋主题模型以及仅关注文本,这些维度之间的关联及其随时间的变化仍不清楚。我们与反钓鱼工作组(APWG)合作,对13个月(2025年6月至2026年6月)内收集的290万封不同的真实世界钓鱼邮件进行了一项以内容为中心的测量研究。我们将每封邮件视为一个由消息文本及其附件组成的复合工件:包括27.2万张图片、14.3万个PDF文件和5.7万个日历邀请。利用一个经过人工标注样本验证的LLM流水线,我们沿着三个维度(主题、CTA和冒充)分析这些组件,检查它们之间的关联,并对照历史数据集测量长期变化。我们发现,攻击者在用于欺骗的手段上趋于多样化,但在受害者应如何响应上趋于一致:没有任何主题超过21.3%的邮件,而单一的CTA——URL导航——占到了73.0%。CTA和冒充的选择以主题为条件。附件扮演三种角色:图片补充消息文本,PDF通过携带借口来替代文本,而日历邀请则通过将交互端点复制到持久介质中来强化文本。从长期来看,发票主题钓鱼的主导CTA已从URL导航转向离线通信,从2015年的6.7%上升到2025年的46.9%。
英文摘要
Phishing remains one of the most pervasive threats to Internet users, and email remains its predominant delivery channel. Email content is the attack surface of phishing: it is what the victim reads and what automated defenses inspect. Yet the composition of modern phishing content is poorly measured. Prior work has characterized dimensions such as theme, call-to-action (CTA), and impersonation, but not at scale, and their associations and temporal changes remain unclear, owing to small or source-specific corpora, bag-of-words topic models, and a focus on text alone. We present a content-focused measurement study of 2.9M distinct real-world phishing emails collected over 13 months (June 2025 - June 2026) in collaboration with the Anti-Phishing Working Group (APWG). We treat each email as a composite artifact comprising message text and its attachments: 272K images, 143K PDFs, and 57K calendar invitations. Using an LLM pipeline validated against human-annotated samples, we analyze these components along three dimensions (theme, CTA, and impersonation), examine the associations among them, and measure longer-term change against a historical dataset. We find that attackers diversify what they use to deceive but converge on how victims should respond: no theme exceeds 21.3% of emails, while a single CTA, URL navigation, accounts for 73.0%. CTA and impersonation choices are conditioned on theme. Attachments play three roles: images supplement the message text, PDFs substitute for it by carrying the pretext, and calendar invitations reinforce it by replicating interaction endpoints into a persistent medium. Over the longer term, the dominant CTA for invoice-themed phishing shifted from URL navigation to offline communication, rising from 6.7% in 2015 to 46.9% in 2025.
发表机构
- University of Tennessee, Knoxville(田纳西大学诺克斯维尔分校)
- Korea University(高丽大学)
机构由 AI 辅助整理,请以论文原文为准。