AI-Assisted Phishing: A Field Methodology for Adversary Simulation

LLM-assisted phishing isn't theoretical anymore. I built a methodology for it at TrustedSec that turned into a billable service. This talk walks through how it works in practice — pretext writing, target research, content generation — using a real engagement with a national enterprise client as the example. I'll cover where the LLM tooling actually helps, where it struggles and requires real operator competency, and what defenders should change.


The talk is built around a real adversary simulation engagement where I cloned an executive's voice from a single podcast appearance, ran a phishing call against the organization's help desk, and walked away with high-privilege network admin credentials approximately five minutes in. I'll cover the full setup — what worked, what didn't, and what I'd do differently.

I built this methodology at TrustedSec, where it grew from an internal experiment into a billable service. A colleague later presented derivative material at Wild West Hackin' Fest for another engagement that he did, where he included aspects of my engagement/methodology into the talk.

This would be my first time presenting the original work myself, including engagement detail not covered in the prior talk.

What I'll cover in 25 minutes:

  • Why real-time voice cloning didn't work and why a soundboard did
  • Extracting clean voice samples from podcast audio
  • Cloning with ElevenLabs and validating the output against source material
  • Building a 60+ clip soundboard from notes on how the target actually spoke
  • The call rig: soft phone, virtual audio cable, color-coded soundboard by emotional tone
  • Dry-run rehearsal with a colleague before the live call
  • The call itself and what made it work in five minutes
  • LLM-assisted pretext writing and OSINT synthesis around the voice work
  • Where defensive controls catch this kind of operation and where they don't

Practitioner-focused. No vendor pitch. Reproducible with any frontier LLM and commercial voice-cloning service.

This is my first conference talk. Ten years of offensive security across TrustedSec, Optiv, JPMorgan Chase, and BMO Harris. GRTE-certified and GCP SME at TrustedSec. Public tooling on GitHub: gcp_identifier, gcp_bqhunter, DarkEnumeration. Guest on TrustedSec's Security Noise podcast discussing AI and offensive security.

Shane Jones

Shane Jones runs Ohm Security Advisory, a security consulting practice in Austin focused on penetration testing, red team operations, AI security, and secure development. Ten years in adversary simulation across TrustedSec, Optiv, JPMorgan Chase, and BMO Harris. Former USAF Security Forces. GRTE-certified. GCP SME.