Cyber Crime

Attackers Using LLMs to Create Phishing Pages in Real Time

Pawan Panwar
February 8, 2026

Featured preview

We alert users to a proof-of-concept (PoC) attack technique that could allow threat actors to employ artificial intelligence (AI) tools to create malicious JavaScript in real time on seemingly harmless websites.

Researchers

“When the first webpage loads in the victim's browser, it requests client-side JavaScript from well-known and reliable LLM clients (such as DeepSeek and Google Gemini); however, the Proof of Concept may work with several models.”

 “Attackers can then use properly crafted prompts that get around security measures to fool the LLM into returning malicious JavaScript snippets. A completely functional phishing page is then produced by assembling and running these snippets in the browser's runtime. This eliminates any observable, static payload.”

 “Careful, quick engineering to get over the LLM's built-in defenses was essential to the attack's effectiveness.”

 “We discovered that straightforward rewording worked quite well. For example, whilst a direct request for "code to exfiltrate credentials" was prohibited, a request for a generic $AJAX POST function was allowed. To maintain the first page's cleanliness, indications of compromise (IoCs), such as Base64-encoded exfiltration URLs, could potentially be concealed inside the prompt itself.”

 

The researchers discovered that they could reword their cues to fool the AI into carrying out malevolent tasks, even though reputable AI programs contain safeguards against abuse.

Unit 42 adds

“This exploit is extremely difficult to defend against due to its dynamic nature and browser runtime assembly. For each victim, this attack mechanism generates a different variation. Every malicious payload is sent over a trusted domain and is dynamically produced and unique.”

 

Threat actors are constantly coming up with new strategies to get around security measures. Security awareness training driven by AI can provide your company with a crucial line of defense against social engineering scams that evade your technical safeguards.

Note: To get a stress-free working environment, you can go for a specially designed tool, “PhishNext,” that provides specialized simulations of phishing attacks so that the users can get used to such attacks and never become a victim of such attacks.

Read More on This Topic

  1. Phishing on Messaging Apps: How Attackers Use Teams, WhatsApp, SMS, and Slack?
  2. How to Identify a Phishing Website? | PhishNext
  3. Top 10 Best Phishing Simulation Tools In 2026
  4. How to Identify Fake Websites: A Beginner’s Guide to URL Safety
  5. Corporate Phishing Simulation Solutions in India
  6. The Hospitality Frontline: Managing Hotel Cybersecurity in the Age of ClickFix
  7. Ransomware Infection Incident Disclosed by Washington Hotel in Japan
  8. What Is Phishing Simulation? Complete Guide for Businesses
  9. Phishing Scam Targets India AI Impact Summit Attendees: Urgent Security Advisory