Unveiling the Underground Phishing Ecosystem: A 12-Year Longitudinal Study of Deep and Dark Web Forums
Dohee Kim, Hui Zhao, Doowon Kim, Sungjae Hwang
Abstract
Phishing is a threat in which attackers masquerade as legitimate entities to steal sensitive data. While understanding the phishing ecosystem is critical for developing effective countermeasures, prior research has largely studied phishing through post-attack data, with limited examination of the attacker's perspective and how phishing campaigns are built. Critically, the Deep and Dark Web (D2Web) serves as the primary marketplace and knowledge-sharing platform where attackers acquire phishing tools (e.g., phishing kits), exchange techniques, and trade compromised credentials. Analyzing D2Web forums therefore provides unique visibility into the supply chain of phishing attacks pre-deployment, enabling proactive understanding of emerging threats and attack methodologies. This study addresses this gap through a comprehensive analysis of 394,034 posts (343,334 unique) collected from 13 D2Web forums spanning 2013 to 2025, from which 70,055 phishing-related posts are identified. We employ a LLM-based approach to efficiently extract key information, including phishing attack components (e.g., credentials, phishing pages, SMTP servers), targeted services (e.g., PayPal, Netflix), and component authors. This extracted data is mapped to a seven-stage attack scenario framework derived from empirical case studies. Our analysis reveals longitudinal trends in component availability, target service distribution, post type evolution, and the most active contributors annually, while characterizing pricing dynamics across different attack components. The results provide the first attacker-centric, macro-level longitudinal analysis of the phishing ecosystem, offering insights into how phishing infrastructure and markets have evolved over more than a decade. These findings contribute to a deeper understanding of the phishing supply chain and inform more effective detection and prevention strategies.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get 48c1824c-e683-4206-a4dd-e0effd402884Related papers
- What's in Phishers: A Longitudinal Study of Security Configurations in Phishing Websites and KitsKyungchan Lim, Kiho Lee, Fujiao Ji, Yonghwi Kwon et al.WWW 2025 · 3 citations
- On SMS Phishing Tactics and InfrastructureAleksandr Nahapetyan, Sathvik Prasad, Kevin Childs, Adam Oest et al.S&P 2024 · 30 citations
- PhishEye: Live Monitoring of Sandboxed Phishing KitsXiao Han, Nizar Kheir, Davide BalzarottiCCS 2016 · 118 citations
- Characterizing and Mitigating Phishing Attacks at ccTLD ScaleGiovane C. M. Moura, Thomas Daniels, Maarten Bosteels, Sebastian Castro et al.CCS 2024 · 7 citations
- Sunrise to Sunset: Analyzing the End-to-end Life Cycle and Effectiveness of Phishing Attacks at ScaleAdam Oest, Penghui Zhang, Brad Wardman, Eric Nunes et al.USENIX Security 2020
