@inproceedings{ai-email:imc25, author = "Hao, Wei and Tran, Van and Rideout, Vincent and Wang, Zixi and Dasbach-Prisk, AnMei and Afifi, M. H. and Yang, Junfeng and Katz-Bassett, Ethan and Ho, Grant and Cidon, Asaf", abstract = "The rapid adoption of large language models (LLMs) has fueled speculation that cybercriminals may utilize LLMs to improve and automate their attacks. However, so far, the security community has had only anecdotal evidence of attackers using LLMs, lacking large-scale data on the extent of real-world malicious LLM usage. In this joint work between academic researchers and Barracuda Networks, we present the first large-scale study measuring AI-generated attacks in-the-wild. In particular, we focus on the use of LLMs by attackers to craft the text of malicious emails by analyzing a corpus of hundreds of thousands of real-world malicious emails detected by Barracuda. The key challenge in this analysis is determining ground truth: we cannot know for certain whether an email is LLM or human-generated. To overcome this challenge, we observe that, prior to the launch of ChatGPT, email text was almost certainly not LLM-generated. Armed with this insight, we run three state-of-the-art LLM detection methods on our corpus and calibrate them against pre-ChatGPT emails, as well as against a diverse set of LLM-generated emails we create ourselves. Since the launch of ChatGPT, all three detection methods indicate that attackers have steadily increased their use of LLMs to generate emails, especially for spam. Using our most precise AI-detection method, we conservatively estimate that at least ∼51\% of spam emails and ∼14\% of business email compromise attacks in our dataset are generated using LLMs, as of April 2025. Finally, analyzing the text of LLM-generated emails, we find evidence that attackers use LLMs to “polish” their emails and to generate multiple versions of the same email message.", title = "Do Spammers Dream of Electric Sheep? Characterizing the Prevalence of {LLM}-Generated Malicious Emails", booktitle = "Proceedings of the 25th ACM Internet Measurement Conference (IMC)", doi = "10.1145/3730567.3732922", pdfurl = "https://dl.acm.org/doi/pdf/10.1145/3730567.3732922", pages = "192--203", year = "2025" }