insidejob
AML.T0052.000 Demonstrated

Spearphishing via Social Engineering LLM

This technique has been demonstrated in research or controlled environments.

Adversaries may turn LLMs into targeted social engineers. LLMs are capable of interacting with users via text conversations. They can be instructed by an adversary to seek sensitive information from a user and act as effective social engineers. They can be targeted towards particular personas defined by the adversary. This allows adversaries to scale spearphishing efforts and target individuals to reveal private information such as credentials to privileged systems.