🤖 AI Summary
This study addresses the lack of large-scale measurement, dimensional correlation analysis, and evolutionary understanding regarding phishing email content composition. Leveraging 2.9 million authentic emails, we construct a human-validated large language model pipeline integrated with multimodal parsing techniques to process both textual content and attachments, achieving the first multidimensional joint analysis of attachment-inclusive corpora. The research quantifies the conditional dependencies between subjects and calls-to-action (CTAs) while tracking their longitudinal evolution. Results indicate that URL navigation dominates as the primary CTA mechanism (73%). Notably, in invoice-themed phishing, the proportion of offline communication CTAs increased from 6.7% in 2015 to 46.9% in 2025, revealing both diversification and convergence characteristics in adversarial strategies over time.
📝 Abstract
Phishing remains one of the most pervasive threats to Internet users, and email remains its predominant delivery channel. Email content is the attack surface of phishing: it is what the victim reads and what automated defenses inspect. Yet the composition of modern phishing content is poorly measured. Prior work has characterized dimensions such as theme, call-to-action (CTA), and impersonation, but not at scale, and their associations and temporal changes remain unclear, owing to small or source-specific corpora, bag-of-words topic models, and a focus on text alone.
We present a content-focused measurement study of 2.9M distinct real-world phishing emails collected over 13 months (June 2025 - June 2026) in collaboration with the Anti-Phishing Working Group (APWG). We treat each email as a composite artifact comprising message text and its attachments: 272K images, 143K PDFs, and 57K calendar invitations. Using an LLM pipeline validated against human-annotated samples, we analyze these components along three dimensions (theme, CTA, and impersonation), examine the associations among them, and measure longer-term change against a historical dataset.
We find that attackers diversify what they use to deceive but converge on how victims should respond: no theme exceeds 21.3% of emails, while a single CTA, URL navigation, accounts for 73.0%. CTA and impersonation choices are conditioned on theme. Attachments play three roles: images supplement the message text, PDFs substitute for it by carrying the pretext, and calendar invitations reinforce it by replicating interaction endpoints into a persistent medium. Over the longer term, the dominant CTA for invoice-themed phishing shifted from URL navigation to offline communication, rising from 6.7% in 2015 to 46.9% in 2025.