Aumentan los casos de phishing impulsados por la IA [¿Qué hacer?]

¿Estás protegido contra el phishing impulsado por IA en 2025?

Los piratas informáticos han aumentado constantemente sus ataques de phishing entre 2022 y 2024, según 1,000% con la mayoría de los ataques dirigidos a las credenciales de los usuarios.

La investigación revela que los ciberataques generados por IA son el ataque más temido por los empleados de TI y los expertos en ciberseguridad en 2025. Fuente.

Los actores maliciosos pueden utilizar plataformas de inteligencia artificial como ChatGPT o DeepSeekเพื่อ para escribir estafas de phishing por correo electrónico más convincentes e incluso configurar dominios de sitios web falsos que suplantan a sitios legítimos.

En 2024, hasta Microsoft estaba siendo suplantado por actores de amenazas para obtener las credenciales del usuario.

Para asegurarse de que usted y su equipo estén protegidos contra el phishing impulsado por IA, analicemos el panorama actual de amenazas y nuestros mejores consejos para proteger la información confidencial.

Cómo están evolucionando los ataques de phishing en 2025

Phishing es un tipo de ciberdelito que explota la percepción de legitimidad de la víctima.

También etiquetados como “ingeniería social” por los profesionales de la ciberseguridad, los ataques de phishing tradicionalmente se han presentado como correos electrónicos legítimos de un colega o una empresa de confianza. Una vez que los piratas informáticos se ganan la confianza de la víctima, presionan a la persona para que entregue datos personales o información sobre la empresa que pueda utilizarse para extorsionar fondos.

El cambiante panorama de amenazas en 2025 ha visto cómo los mensajes de suplantación de identidad (phishing) se entrelazan con el aprendizaje automático y los grandes modelos de lenguaje, lo que ayuda a los piratas informáticos a crear rápida y fácilmente correos electrónicos, llamadas telefónicas o videollamadas de phishing generadas por IA.

El 75% de los ciberataques comenzó con un correo electrónico de phishing en 2024, lo que demuestra que el envío de un correo electrónico sospechoso sigue siendo el método preferido de un pirata informático para infiltrarse en una organización. Con la inteligencia artificial, los ataques son cada vez más sofisticados en sus esfuerzos por propagar ransomware y malware, y comprometer la seguridad del correo electrónico.

La inteligencia artificial está haciendo que los ataques de phishing sean más convincentes

A atrás han quedado los días en los que se podía identificar un correo electrónico de phishing por faltas de ortografía o gramática incorrecta. Los estafadores están utilizando IA generativa orquestar ataques de spear phishing convincentes, por lo general, con solo unos pocos datos personales encontrados en línea.

Según nuestro informe sobre inteligencia de amenazas externas, el 67,4% de todos los ataques de phishing perpetrados en 2024 utilizaron algún tipo de inteligencia artificial.

Las herramientas de inteligencia artificial como ChatGPT se utilizan para centrarse en las principales preocupaciones de los empleados y convertir esos puntos débiles en un correo electrónico de suplantación de identidad (phishing) convincente y libre de errores gramaticales. La eficacia de estos mensajes de phishing hace que sea más probable que los destinatarios hagan clic en un enlace malicioso.

Un investigador de ciberseguridad descubrió que solo se necesitaron cinco indicaciones para instruir a ChatGPT a fin de que generara correos electrónicos de phishing para sectores industriales específicos.

Ejemplo de un ataque de spear-phishing utilizando IA generativa. Fuente.

En 2024, una multinacional fue víctima de una estafa de deepfake lo que supuso para la empresa unos daños y perjuicios por valor de $25 millones. Se invitó al empleado a participar en una conferencia telefónica con otros miembros del equipo directivo. Durante la llamada, el director financiero autorizó el pago de $25 millones por lo que el empleado consideraba un motivo empresarial legítimo.

Más tarde se descubrió que todos los participantes en la llamada eran un "deepfake": los estafadores habían recopilado datos disponibles públicamente en línea de plataformas de redes sociales como LinkedIn y luego habían introducido los datos en tecnología de inteligencia artificial para crear videos y audios falsos coincidentes. Para el empleado, los estafadores miró y sonaban idénticos a sus colegas de la vida real.

Hasta los profesionales de la ciberseguridad tendrían dificultades para distinguir entre las estafas de vishing y phishing y las comunicaciones legítimas. Según Reuters, 97% de organizaciones tienen dificultades para verificar la identidad.

En este panorama cambiante de amenazas cibernéticas, la IA ha creado un obstáculo significativo para las empresas. Es importante considerar cómo se utiliza la IA en los ataques de phishing para que las empresas puedan encontrar nuevas formas de eludir los ataques de ingeniería social.

Las herramientas de IA que ayudan a los ciberdelincuentes

Las herramientas de inteligencia artificial utilizadas por empresas legítimas para ayudar a los empleados están siendo utilizadas por ciberdelincuentes para estafar a las empresas.

Estas son algunas de las herramientas clave que los estafadores ya han utilizado en ataques de phishing:

DeepSeek: DeepSeek, un chatbot de inteligencia artificial abierto procedente de China, ha sido cooptado por estafadores para crear correos electrónicos de suplantación de identidad (phishing), convertir texto en audio y vídeo para ataques de vishing, e incluso crear dominios falsos para obtener credenciales.

ChatGPT and other generative AI platforms: Generative AI tools help threat actors easily and quickly churn out emails, code, or other materials to deceive users and gain entry to systems or credentials. AI can also be used to automate attacks, adapt phishing tactics in real-time, and collect reconnaissance on targets.

Malicious LLMs WormGPT, FraudGPT, Fox8, DarkBERT, and others: Threat actors have created malicious large language learning models (LLMs) to help them create malware, malicious code, and other illegal software.

AI-powered voice cloning and phone call spoofing apps: Hackers are using voice cloning tools found online to deceive victims. Scammers scrape publically available data of executives from social media to impersonate them on phone calls. Spoofing apps help hackers appear to be calling from the phone number of whoever they are impersonating.

When DeepSeek was used to harvest credentials…

This year, threat actors set up lookalike DeepSeek sites to trick unsuspecting users into handing over sensitive information like credentials and logins.

CybelAngel‘s requests for takedowns of fake domains surged by 116% in 2024 compared to the previous year. Fake domains created by AI technology are becoming a real problem.

In one case, threat researchers came across malicious Python packages from a fake DeepSeek application. Within minutes, the cybersecurity professionals located the packages and removed them within an hour.

Fake DeepSeek packages infiltrated the network of threat landscape researchers. Fuente.

The packages, however, were still downloaded 200+ times before they were removed. The análisis revealed that the fake DeepSeek packages hid malicious functions designed to collect user and system data.

The malware was designed to send the stolen data to a command and control server through an integration platform. The attack was aimed at developers and those with cybersecurity knowledge, capitalizing on the hype of DeepSeek.

Phone spoofing was used to impersonate an executive…

Artificial intelligence-based software was used to impersonate an executive at a multinational company, helping hackers get away with thousands of dollars.

The employee was contacted on the phone by who he thought was his boss at the German-based parent company. He was asked to wire $243,000 into the bank account of a Hungarian supplier.

The AI technology was able to imitate the executive‘s slight German accent and even the melody of his voice.

Phone call spoofing and AI voice cloning made it impossible for the employee to suspect a phishing attack.

Malicious GenAI is being used to orchestrate cyberattacks…

On the dark web, hackers have created their own generative AI platform. FraudGPT was first advertised in 2023 to help scammers launch phishing campaigns.

FraudGPT promoted on a hacker forum. Fuente.

With similar interfacing to ChatGPT, FraudGPT doesn‘t have any guardrails to stop it from complying with requests like writing malicious code or creating phishing emails that appear to be from a reputable company.

WormGPT has likewise been used to automate personalized emails for phishing attacks and create malware and malicious code. A cybersecurity team tested WormGPT and found it could generate Python scripts capable of credential harvesting.

Los piratas informáticos dependen de la ingeniería social para sus ataques

If you received a call from your manager that looked and sounded real, how would you be able to tell it apart from a fake?

Threat actors rely on their targets trusting the phishing attempt—making it appear as normal as possible. Recognizing coercive cues during encounters can reveal the scammers‘ true intentions.

How social engineering is used in attacks:

Authority bias: Threat actors impersonate figures of authority, such as executives or IT managers, to trick victims into handing over sensitive information.

Reciprocity bias: Social engineers prey on our human tendency to help others. In exchange for information, hackers may offer rewards or other support.

Social proof: Threat actors exploit the tendency to follow others’ actions by providing “evidence” that other colleagues have already approved certain actions.

Urgency bias: Hackers put time pressure on victims to make them act in the moment. They may ask to transfer funds quickly or provide sensitive data without the regular approval loops.

Optimism bias: Cybercriminals take advantage of people’s tendency to overestimate positive outcomes and underestimate risks. Examples include fake job ads or insider information scams.

Mejores prácticas para prevenir ataques de phishing en 2025

Threat actors use social media and corporate leadership materials with AI to make their phishing attempts look more legitimate.

It‘s important to secure your accounts and IT infrastructure and be on the lookout for hyper-realistic phishing materials.

Here are some best practices for preventing ai-enabled phishing attempts:

  1. Enable Multi-factor Authentication (MFA): MFA adds an extra layer of security by requiring multiple forms of verification making it harder for threat actors to infiltrate systems. While MFA won’t stop phishing threats, it will prevent against unauthorized access.
  2. Realiza evaluaciones de vulnerabilidad periódicas Pruebe regularmente sus sistemas para identificar y parchear vulnerabilidades antes de que los atacantes puedan explotarlas.
  3. Educa a tu equipo Train employees to recognize phishing attempts and other social engineering tactics used by APT groups, and to follow data protection protocols. Simulations of phishing attacks, also called Red Teaming, can be successful by providing real-world scenarios.
  4. Invertir en inteligencia de amenazas: Use services that provide real-time data on potential threats targeting your industry, such as CybelAngel. Managing digital risk with actionable threat intelligence across surface, deep, and dark web sources ensures that any breach is detected before it‘s too late.

Descarga nuestro nuevo informe anual

Nuestro 2025 External Threat Intelligence Report, authored by CybelAngel‘s CISO, Todd Carroll, found that integrated AI-detection tools are the most effective way to identify and report AI-powered phishing attempts.

In the ever-evolving landscape of cybersecurity, staying ahead of emerging threats is crucial.

Our comprehensive 2025 report delves into the latest trends and tactics in AI-enhanced phishing, providing invaluable insights and actionable strategies to protect your organization.

Download your copy of the report here.

Sobre el autor