Saved in:
| Main Author: | |
|---|---|
| Format: | Recurso digital |
| Language: | |
| Published: |
Zenodo
2026
|
| Online Access: | https://doi.org/10.5281/zenodo.18144132 |
| Tags: |
Add Tag
No Tags, Be the first to tag this record!
|
Table of Contents:
- <p><a href="https://ijetrm.com/issues/files/Jan-2026-04-1767511325-JAN06.pdf" target="_blank" rel="noopener">Large language models (LLMs)</a> have essentially changed the game in natural-language generation. So far, open<br>models and a few powerful commercial assistants have been able to write emails, code, and answer questions<br>with a human-level fluency. Sadly, the factors that bring about the great success of LLMs - contextual<br>awareness, coherence, and ease of use - are the very factors that are being exploited by adversaries.<br>Phishing as the most common method of social engineering is still going strong: around 96 % of attacks are<br>delivered by emails, and lately, several studies have inferred that 82 % of phishing emails are written with the<br>help of LLMs . Results of evaluations conducted in mid-2025 showed that messages of spear-phishing generated<br>by LLMs had click-through rates of more than 30 %, thus, they were more successful than those created by<br>humans . Simultaneously, the underground communities are jailbreaking open models and launching “dark<br>LLM” services like WormGPT, FraudGPT, and DarkBERT, which get rid of safety guardrails and provide<br>ready-made prompts for business-email compromise, code obfuscation, and malware generation, respectively, as<br>their main functionalities. Besides that, the latest studies reveal that autonomous prompt-injection worms can go<br>on RAG systems, and malware examples like PromptLock and LameHug can have LLMs as a part of their<br>payload that they directly embed into the payload.<br>This article goes through how LLMs are exploited for phishing, social engineering, and malware, explains the<br>recent case studies, and talks about the ethics of building the resilient AI systems. We, by integrating academic<br>research, industry reports, and dark-web observations, give a well-structured overview of the current<br>capabilities, point out the gaps in the defense, and suggest the responsible AI development as a way forward.</p>