4 ms·
So far, it seems to be a bog-standard phishing email, with not much novelty or sophistication, seems the people running the operation got very lucky with their
by diggan 1y ago
So far, it seems to be a bog-standard phishing email, with not much novelty or sophistication, seems the people running the operation got very lucky with their victims though.
I'm starting to think we haven't even seen the full scope of it yet, two authors confirmed as compromised, must be 10+ out there we haven't heard of yet?
- skeeter2020 1y ago>> So far, it seems to be a bog-standard phishing email The fact this is NOT the standard phishing email shows how low the bar is: 1. the text of the email reads like one you'd get from npm in the tone, format and lack of obvious spelling & grammatical errors. It pushes you to move quicker than you might normally, without triggering the typical suspicions. 2. the landing domain and website copy seem really close to legit, no obfuscated massive subdomain, no uncanny login screen, etc. All the talk of AI disrupting tech; this is an angle where generative AI can have a massive impact in democratizing the global phishing industry. I do agree with you that there's likely many more authors who have been tricked and we haven't seen the full fallout.
- r_lee 1y agoHow does AI relate to this in any way? you can easily clone websites by just copying via devtools, like seriously same with just copying email HTML it's actually easier to make it looke exactly the same vs different in some ways
- mvieira38 1y agoYou can make your phishing bot write tailor-made messages and even respond
- deleted 1y ago[deleted]
- diggan 1y agoBoth of those points are fairly common in phishing emails, at least the ones I receive. Cloning the HTML/CSS for phishing has been done for as long as I've been able to receive emails, don't even need LLMs for that :)
- spoaceman7777 1y agoIt's just a phishing email... there isn't anything novel going on here. Also, I really don't see what this has to do with gen AI, or what "democratizing the global phishing industry" is supposed to mean even. Is this comment AI generated?
- ApolloFortyNine 1y agoIf your someone who barely speaks English in a third world country running a phishing campaign, you can have chatgpt write you a professional sounding email in 10 seconds. If you convince it your running a phishing test you can probably even have a back and forth about the entire design and wording of the email and phishing site. That's what I'm guessing OP meant.
- malshe 1y ago> the text of the email reads like one you'd get from npm in the tone, format and lack of obvious spelling & grammatical errors. As a university professor whose email address is public, I've been regularly getting phishing emails for years. Many of these are targeted and devoid of any spelling or grammatical errors. I am sure generative AI is making writing these emails easier but by how much is unknown.
- IshKebab 1y agoProbably the differentiating factor here is that the phishing message was very plausible. Normally they're full of spelling mistakes and unprofessional grammar. The domain was also plausible. I think where they got lucky is > In hindsight, the fact that his browser did not auto-complete the login should have been a red flag. A huge red flag. I wonder if browsers should actually detect if you're putting login details for site A manually into site B, and give you a "are you sure this isn't phishing" warning or something? I don't quite understand how the chalk author fell for it though. They said > This was mobile, I don't use browser extensions for the password manager there. So are there mobile password managers that don't even check the URL? I dunno how that works...
- hiccuphippo 1y agoMy guess is their password manager is a separate app and they use the clipboard (or maybe it's a keyboard app) to paste the password. No way for the password manager to check the url in that case.
- stanac 1y agoYou are probably right. Still browser vendors or even extension devs can create a system where username hash and password hash are stored and checked on submit to warn for phishing. Not sure if I would trust such extension, except in case it's FF recommended and verified extension.
- 0cf8612b2e1e 1y agoI use a separate app like this because I do not fully trust browser security. The browser is such a tempting hacking target (hardened, for sure) that I want to know my vault lives in an offline-only area to reduce chance of leaks. Is there some middle ground where I can get the browser to automatically confirm I am on a previously trusted domain? My initial thought is that I could use Firefox Workspaces for trusted domains. Limited to the chosen set of urls. Which I already do for some sites, but I guess I could expand it to everything with a login.
- 1y ago
- polynomial 1y agoThe article says the victim used 2fa. How did the attacker know their 2fa in order to send them a fake 2fa request?
- fastest963 1y agoThey MITM the real sign-in on NPM. So NPM actually sent them a 2FA but the user entered it on the phishing site. The attacker then relayed that to the real NPM.