PhishParrot: A User Profile-Optimizing Crawler Leveraging LLMs Against Cloaked Phishing Sites
Hiroki Nakano, Takashi Koide, Daiki Chiba · IEEE Access · 2026
Phishing attackers widely deploy cloaking techniques that serve phishing content only to targeted victims while presenting benign pages to security scanners, causing even advanced detectors to fail.We present PhishParrot, a retrieval-augmented crawling system that bypasses cloaking by inferring a victim-like access profile for each suspicious URL. PhishParrot performs a preliminary crawl to extract domain, network, and HTML features; retrieves semantically similar successful and failed crawl cases from a continuously growing database; prompts a Large Language Model (LLM) to synthesize an optimal user profile (HTTP headers, geolocation, and network type) from contrastive evidence; and re-crawls the URL under the inferred profile. We evaluate PhishParrot during a nine-month online deployment (May 2025–January 2026) on 163,586 labeled URLs; of the 66,994 phishing URLs, 40% exhibit cloaking. PhishParrot achieves a de-cloaking success rate of 90.8%, improving by 59.2 percentage points over typical user system and 82.1 percentage points over a standard analysis system. Across five downstream phishing detectors, macro-averaged F1 improves from 55.9% (typical user system) to 77.5%, with true-positive rate gains of 29–43 percentage points on cloaked URLs. Weekly de-cloaking performance remains stable throughout deployment (standard deviation 2.7 percentage points), demonstrating that retrieval-augmented, profile-driven crawling provides a practical and sustainable content-acquisition layer for phishing triage under cloaking.