article Open access

Exemplifying Emerging Phishing: QR-Based Browser-in-the-Browser (BiTB) Attack

  • IEEE Networking Letters
  • Institute of Electrical and Electronics Engineers
Research footprint

At a glance

Citations
1
References
0
Comments
0
Paper overview

Abstract

Lately, cybercriminals constantly formulate productive approaches to exploit individuals. This article exemplifies an innovative attack, namely QR-based Browser-in-The-Browser (BiTB), using proficiencies of Large Language Model (LLM) i.e. Google Gemini. The presented attack is a fusion of two emerging attacks: BiTB and Quishing (QR code phishing). Our study underscores attack’s simplistic implementation utilizing malicious prompts provided to Gemini-LLM API. Moreover, we presented a case study and performed an experiment to comprehend the attack execution. We also provided the performance evaluation of attack success by comparing Gemini-LLM with GPT and static website. The findings of this work obligate the researchers’ contributions in confronting this type of phishing attempts through LLMs.

Record transparency

Publication details

DOI
10.1109/lnet.2025.3605640
OpenAlex
W4413966888
Document type
article
Language
EN
Source
IEEE Networking Letters
Last metadata update
Community

Comments

Log in to join the discussion.

  1. No comments yet. Start the discussion.