Papers for

cyber threat intelligence analysts

Papers whose findings have a practical use for this group, as judged from the abstract. Open a paper to read what it means in practice.

Phishing emails use varied themes but mainly urge clicking links

A Large-Scale Empirical Study of Modern Phishing Email Content

Abstract: Phishing remains one of the most pervasive threats to Internet users, and email remains its predominant delivery channel. Email content is the attack surface of phishing: it is what the victim reads and what automated defenses inspect. Yet the composition of modern phishing content is poorly measured. Prior work has characterized dimensions such as theme, call-to-action (CTA), and impersonation, but not at scale, and their associations and temporal changes remain unclear, owing to small or source-specific corpora, bag-of-words topic models, and a focus on text alone. We present a content-focused measurement study of 2.9M distinct real-world phishing emails collected over 13 months (June 2025 - June 2026) in collaboration with the Anti-Phishing Working Group (APWG). We treat each email as a composite artifact comprising message text and its attachments: 272K images, 143K PDFs, and 57K calendar invitations. Using an LLM pipeline validated against human-annotated samples, we analyze these components along three dimensions (theme, CTA, and impersonation), examine the associations among them, and measure longer-term change against a historical dataset. We find that attackers diversify what they use to deceive but converge on how victims should respond: no theme exceeds 21.3% of emails, while a single CTA, URL navigation, accounts for 73.0%. CTA and impersonation choices are conditioned on theme. Attachments play three roles: images supplement the message text, PDFs substitute for it by carrying the pretext, and calendar invitations reinforce it by replicating interaction endpoints into a persistent medium. Over the longer term, the dominant CTA for invoice-themed phishing shifted from URL navigation to offline communication, rising from 6.7% in 2015 to 46.9% in 2025.

Fri 25 SeptCryptography and Security
The gist
Phishing emails trick people by pretending to be trustworthy sources, and most come through email. This study by the authors looked closely at nearly 3 million real phishing emails to understand what these messages say and how they try to fool victims. They found that while phishing emails cover many topics, most of them ask people to click on a link. The study also shows how attackers use images, PDFs, and calendar invites in different ways to support their tricks, and how phishing tactics have shifted over time.
Open → 2609.30683v1

Infostealer malware compromises gaming and high-value organization accounts worldwide

A Data-Driven Analysis of Infostealer Malware Victims

Abstract: Infostealer malware infects devices worldwide and harvests their most sensitive contents: credentials, browser sessions, private keys, and access certificates. Yet its impact on victims remains difficult to study without an ethical, legal, and curated research dataset. To close this gap, we build a privacy-preserving pipeline that turns illicitly sourced infostealer logs into a reproducible research artifact, minimizing sensitive data while preserving measurement utility, and use it to construct a dataset of 170,298 victims from logs of multiple infostealer families. Analyzing these victims, we find that the most compromised services mirror the world's most popular platforms, with gaming and entertainment services strongly overrepresented. Within the sample we identify compromised credentials for high-value organizations, including law-enforcement domains, government and military services, and all eight Ivy League universities, as well as substantial exposure of security-critical infrastructure and of financial, remote-access, and development platforms. Victims also show widespread credential reuse and significant revictimization risk, overlapping with phishing and ransomware victim populations. We release the first anonymized victim-level infostealer dataset under controlled access to enable ethical, privacy-preserving, and reproducible research on information security and victim behavior.

Thu 24 SeptCryptography and Security
The gist
Infostealer malware steals sensitive information like passwords and private keys from infected devices. The authors created a safe way to study these stolen data records without exposing sensitive details. They analyzed over 170,000 victims and found that popular services, especially gaming and entertainment platforms, are heavily targeted. They also uncovered compromised credentials from important organizations like government, law enforcement, and major universities. The study highlights risks from reusing passwords and overlap with other cyber threats like phishing and ransomware.
Open → 2609.30070v1