circumvented detection from mainstream APEs and
assess their efficacy using a bespoke framework. This
paper a lso underlines poten tial strategies for bypass-
ing APE detection. Future studies could further delve
into these avenues, investigating real-world ap plica-
tion of these cloaking techniques or conducting large-
scale evaluations of these methodologies.
Acharya, B. and Vadrevu, P. (2021). Phishprint: Evad-
ing phishing detection crawlers by prior profiling. In
USENIX Security Symposium, pages 3775–3792.
Al-Ahmadi, S., Alotaibi, A., and Alsaleh, O. (2022). Pdgan:
Phishing detection with generative adversarial net-
works. IEEE Access, 10:42459–42468. https://doi.
Alabdan, R. (2020). Phishing attacks survey: Types,
vectors, and technical approaches. Future Internet,
Ali, M. M., Chitale, B., Ghasemisharif, M., Kanich, C.,
Nikiforakis, N., and Polakis, J. (2023). Navigating
murky waters: Automated browser feature testi ng for
uncovering tracking vectors. In P roceedings 2023
Network and Distributed System Security Symposium.
Network and Distributed System Security Symposium,
San Diego, CA, USA. htt ps://
APWG (2017). Phishing activity trends report, 4th quarter
APWG (2022). Phishing activity trends r eport, 4th quar-
ter 2021.
Bell, S. and Komisarczuk, P. (2020). An analysis of phish-
ing blacklists: Google safe browsing, openphish, and
phishtank. In Proceedings of the Australasian Com-
puter Science Week Multiconference, ACSW ’20, New
York, NY, USA. Association for Computing Machin-
Freeze, D. (2018). Cybercrime To Cost
The World $10.5 Trillion Annually By
cybercrime-damages-6-t r illion-by-2021/.
Gupta, S., Singhal, A., and Kapoor, A. (2016). A litera-
ture survey on social engineering attacks: Phishing
attack. In 2016 International Conference on Com-
puting, Communication and Automation (IC CCA),
pages 537–540.
Han, X., Kheir, N., and Balzarotti, D. (2016). PhishEye:
Live Monitoring of Sandboxed Phishing Kit s. In Pro-
ceedings of the 2016 ACM SIGSAC Conference on
Computer and Communications Security, CCS ’16,
pages 1402–1413, New York, NY, US A . Association
for Computing Machinery.
Lin, X., Ilia, P. , Solanki, S., and Polakis, J. (2022). Phish in
sheep’s clothing: Exploring the authentication pitfalls
of browser fingerprinting. In 31st USENIX Security
Symposium (USENIX Security 22), pages 1651–1668.
Maroofi, S ., Korczy
nski, M., and Duda, A. (2020). Are you
human? resilience of phishing detection to evasion
techniques based on human verification. In Proceed-
ings of the ACM Internet Measurement Conference,
IMC ’20, page 78–86, New York, NY, USA. Asso-
ciation for Computing Machinery.
Oest, A., Safaei, Y., Doupé, A., Ahn, G.-J., Wardman, B.,
and Tyers, K. (2019). Phishfarm: A scalable frame-
work for measuring the effectiveness of evasion tech-
niques against browser phishing blacklists. In 2019
IEEE Symposium on Security and Privacy (SP), pages
Oest, A., Safaei, Y., Zhang, P., Wardman, B., Tyers, K.,
Shoshitaishvili, Y., Doupé, A., and Ahn, G. (2020a).
Phishtime: Continuous longitudinal measurement of
the effectiveness of anti-phishing blacklists. In Pro-
ceedings of the 29th USENIX Security Symposium,
Proceedings of the 29th USENIX Security Sympo-
sium, pages 379–396. USENIX Association.
Oest, A., Safei, Y., Doupé, A., Ahn, G.-J., Wardman, B.,
and Warner, G. (2018). Inside a phisher’s mind:
Understanding the anti-phishing ecosystem through
phishing kit analysis. In 2018 APWG Symposium
on Electronic Crime Research (eCrime), pages 1–12.
Oest, A., Zhang, P., Wardman, B., Nunes, E., Burgis,
J., Zand, A., Thomas, K., Doupé, A., and Ahn, G.
(2020b). Sunrise to sunset: Analyzing the end-to-
end life cycle and effectiveness of phishing attacks at
scale. In Proceedings of the 29th USENIX Security
Symposium, Proceedings of the 29th USENIX Secu-
rity Symposium, pages 361–377. USENIX Associa-
Pujara, P. and Chaudhari, M. (2018). Phishing website
detection using machine learning: A review. In-
ternational Journal of Scientific Research in Com-
puter Science, Engineering and Information Technol-
ogy, 3(7):395–399.
World Economic Forum (2020). Partnership against
Zhang, P., Oest, A., Cho, H., Sun, Z., Johnson, R., Ward-
man, B., Sarker, S., Kapravelos, A., Bao, T., Wang, R.,
Shoshitaishvili, Y., Doupé, A., and Ahn, G.-J. (2021).
Crawlphish: Large-scale analysis of client-side cloak-
ing techniques in phishing. In 2021 IEEE Sympo-
sium on Security and Privacy (SP), pages 1109–1124.