logo

Attackers Can Use LLMs to Generate Phishing Pages in Real Time

ID: eda5ca24-e20f-5433-8704-81a316ab7771

STIX ID: report--eda5ca24-e20f-5433-8704-81a316ab7771

Feed Name: KnowBe4 Blog

Threat Score
35/100

Date Published: 2026-02-05

Date Updated: 2026-04-28

Author: KnowBe4 Team

...
...

Unit 42 demonstrates a proof-of-concept attack where benign webpages request client-side JavaScript from trusted LLM services (e.g., DeepSeek, Google Gemini); attackers use carefully engineered prompts to bypass safety guardrails and return malicious JS snippets that are assembled and executed in the browser to render fully functional phishing pages with no static, detectable payload, creating unique, hard-to-detect variants per victim and posing a significant defense challenge.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.