2024/08/21 by Theodore Longtchi, Longtchi, Theodore, Shouhuai Xu +1
Computer Science · Decision Sciences · Social Sciences · #Cryptography and Security (cs.CR) #FOS: Computer and information sciences #Misinformation and Its Impacts #Personal Information Management and User Behavior #Spam and Phishing Detection
paper · pdf · doi:10.48550/arxiv.2408.11584
openalex publication_date 2024/08/21 · openalex created_date 2024/12/16 · openalex updated_date 2026/07/28
Cyber attacks, including cyber social engineering attacks, such as malicious emails, are always evolving with time. Thus, it is important to understand their evolution. In this paper we characterize the evolution of malicious emails through the lens of Psychological Factors, PFs, which are humans psychological attributes that can be exploited by malicious emails. That is, attackers who send them. For this purpose, we propose a methodology and apply it to conduct a case study on 1,260 malicious emails over a span of 21 years, 2004 to 2024. Our findings include attackers have been constantly seeking to exploit many PFs, especially the ones that reflect human traits. Attackers have been increasingly exploiting 9 PFs and mostly in an implicit or stealthy fashion. Some PFs are often exploited together. These insights shed light on how to design future defenses against malicious emails.