Phishing Vs. Legit: Comparative Analysis of Client-Side Resources of Phishing and Target Brand Websites
Kyungchan Lim, Jaehwan Park, Doowon Kim
Abstract
Phishing attacks have persistently remained a prevalent and widespread cybersecurity threat for several years. This leads to numerous endeavors aimed at comprehensively understanding the phishing attack ecosystem, with a specific focus on presenting new attack tactics and defense mechanisms against phishing attacks. Unfortunately, little is known about how client-side resources (e.g., JavaScript libraries) are used in phishing websites, compared to those in their corresponding legitimate target brand websites. This understanding can help us gain insights into the construction and techniques of phishing websites and phishing attackers' behaviors when building phishing websites. In this paper, we gain a deeper understanding of how client-side resources (especially, JavaScript libraries) are used in phishing websites by comparing them with the resources used in the legitimate target websites. For our study, we collect both client-side resources from phishing websites and their corresponding legitimate target brand websites for 25 months: 3.4M phishing websites (1.1M distinct phishing domains). Our study reveals that phishing websites tend to employ more diverse JavaScript libraries than their legitimate websites do. However, these libraries in phishing websites are older (nearly 21.2 months) and distinct in comparison. For example, Socket.IO is uniquely used in phishing websites to send victims' information to an external server in real time. Furthermore, we find that a considerable portion of them still maintain a basic and simplistic structure (e.g., simply displaying a login form or image), while phishing websites have significantly evolved to bypass anti-phishing measures. Finally, through HTML structure and style similarities, we can identify specific target webpages of legitimate brands that phishing attackers reference and use to mimic for their phishing attacks. CCS CONCEPTS • Security and privacy → Web application security.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 847ec3cd-4619-469f-9baf-cbefcb97e294Cited by top-tier papers4
- 7 Days Later: Analyzing Phishing-Site Lifespan After DetectedKiho Lee, Kyungchan Lim, Hyoungshick Kim, Yonghwi Kwon et al.WWW 2025 · 5 citations
- What's in Phishers: A Longitudinal Study of Security Configurations in Phishing Websites and KitsKyungchan Lim, Kiho Lee, Fujiao Ji, Yonghwi Kwon et al.WWW 2025 · 3 citations
- Anti-Phishing Training (Still) Does Not Work: A Reproduction of Phishing Training Inefficacy Grounded in the NIST Phish ScaleAndrew T. Rozema, James C. DavisWWW 2026 · 1 citation
- Evaluating the Effectiveness and Robustness of Visual Similarity-based Phishing Detection ModelsFujiao Ji, Kiho Lee, Hyungjoon Koo, Wenhao You et al.USENIX Security 2025
Builds on15
- Internet Jones and the Raiders of the Lost Trackers: An Archaeological Study of Web Tracking from 1996 to 2016Ada Lerner, Anna Kornfeld Simpson, Tadayoshi Kohno, Franziska RoesnerUSENIX Security 2016 · 273 citations
- Thou Shalt Not Depend on Me: Analysing the Use of Outdated JavaScript Libraries on the WebTobias Lauinger, Abdelberi Chaabane, Sajjad Arshad, William Robertson et al.NDSS 2017 · 183 citations
- Hiding in Plain Sight: A Longitudinal Study of Combosquatting AbusePanagiotis Kintis, Najmeh Miramirkhani, Charles Lever, Yizheng Chen et al.CCS 2017 · 166 citations
- Phishpedia: A Hybrid Deep Learning Based Approach to Visually Identify Phishing WebpagesYun Lin, Ruofan Liu, Dinil Mon Divakaran, Jun Yang Ng et al.USENIX Security 2021 · 164 citations
- PhishFarm: A Scalable Framework for Measuring the Effectiveness of Evasion Techniques against Browser Phishing BlacklistsAdam Oest, Yeganeh Safaei, Adam Doupé, Gail-Joon Ahn et al.S&P 2019 · 129 citations
Related papers
- CrawlPhish: Large-scale Analysis of Client-side Cloaking Techniques in PhishingPenghui Zhang, Adam Oest, Haehyun Cho, Zhibo Sun et al.S&P 2021 · 1 citation
- PhishTime: Continuous Longitudinal Measurement of the Effectiveness of Anti-phishing BlacklistsAdam Oest, Yeganeh Safaei, Penghui Zhang, Brad Wardman et al.USENIX Security 2020
- SCAMMAGNIFIER: Piercing the Veil of Fraudulent Shopping Website CampaignsMarzieh Bitaab, Alireza Karimi, Zhuoer Lyu, Adam Oest et al.NDSS 2025
- Unveiling the Underground Phishing Ecosystem: A 12-Year Longitudinal Study of Deep and Dark Web ForumsDohee Kim, Hui Zhao, Doowon Kim, Sungjae HwangWWW 2026
- U Can't Debug This: Detecting JavaScript Anti-Debugging Techniques in the WildMarius Musch, Martin JohnsUSENIX Security 2021 · 8 citations
