AI tools are drastically improving the speed of the reconnaissance stage of targeted social engineering attacks, according to researchers at ESET. Attackers can use these tools to trawl the internet for publicly available information about potential victims, and incorporate this information into personalized spear phishing attacks.
“[L]arge language models (LLMs) are experts at piecing together the kind of information that fraudsters need to make their scams work,” ESET says. “They can profile large numbers of potential victims in little time, collecting relevant pictures, videos, and info on personal interests, work, and family and friends that could be leveraged. AI can also help to design the social engineering scripts used by fraudsters, enabling them to sound convincing over email/social media or other channels even if they’re non-native speakers. It offers an end-to-end fraud pipeline.”
ESET offers the following advice to help users minimize the potential impact of social engineering attacks:
- “Ensure your social profiles can’t be publicly accessed, to limit AI’s ability to find any information or images/videos contained within
- Be judicious in what you share on social media; things like birth dates, children’s schools, holidays and similar events should be off limits
- Be aware that photos may contain information in them that could be used to identify addresses, vehicle details, etc
- Avoid posting anything that may be used to link your personal and professional lives
- Use multi-factor authentication and strong, unique passwords to add an extra layer of security on your accounts
- Don’t accept friend/follower requests from anyone you don’t know. Or if you’re curious, approach them via a separate channel”
ESET has the story: https://www.welivesecurity.com/en/privacy/ai-powered-osint-why-everyone-viable-target-fraud/
