049 - How Do Attackers Use Local LLMs to Phish At Scale? episode artwork

EPISODE · Jun 19, 2026 · 1H 2M

049 - How Do Attackers Use Local LLMs to Phish At Scale?

from SysAdmin Weekly · host Andy Syrewicze and Eric Siron

Ask Claude or ChatGPT to write a phishing email and it politely refuses; pull the right open-weight model onto your own laptop and that refusal layer simply does not exist in many cases.Andy brings his InfoSecurity Europe session to the show, and Eric Siron joins to walk through how threat actors run local LLMs on their own hardware to generate targeted spear phishing at scale, in any language, with no internet connection and no guardrails. The guys break down what the attack workflow actually looks like, why these capabilities never disappear once a model is downloaded, and where the real defensive line sits. Spoiler: "spot the typo" awareness training is dead, and verification culture plus strong email authentication is what carries the load now.## Chapters:00:00:00 - Cold Open: Local LLMs and Phishing at Scale00:01:37 - Welcome Back and InfoSecurity Europe00:03:55 - News React: Washington Pumps the Brakes on Fable00:06:46 - News React: NY Ghost Gun Printing Law and Google AI Liability00:12:07 - Nerd Hour: Camera Gear and Mac Studio Dreams00:13:27 - Nerd Hour: Building the InfoSec Demo00:15:55 - Show Plugs and Community Links00:17:00 - Main Topic: What Local LLMs Actually Are00:21:23 - The Guardrail Gap: Cloud Refuses, Local Complies00:26:55 - The Demo: 15 Tailored Spear Phishing Lures in 90 Seconds00:30:04 - Why These Capabilities Never Go Away00:32:59 - AI on the Defensive Side00:39:01 - Voice Cloning, Deepfakes, and SPF for Phones00:46:20 - The Low-Tech Deepfake Defense00:47:26 - Why Spot-the-Typo Training Is Dead00:50:09 - Verification Culture and Email Authentication00:54:32 - Common Questions: Legality, Detection, and Adoption01:00:18 - Wrap Up: Stay Safe Out There## Resources / Show Notes:- Ollama, the easiest way to run open models locally: https://ollama.com- Hugging Face, open repository of machine learning models: https://huggingface.co- OpenCode, terminal coding agent that runs against local models: https://opencode.ai- Evilginx, reverse-proxy phishing framework referenced in the demo: https://github.com/kgretzky/evilginx2- SysAdmin Weekly Episode 024 - On-Prem AI with Ollama (Spotify): https://open.spotify.com/episode/1Huz7fy7axxOqjXei1HLI0- SysAdmin Weekly - all show links in one place: https://www.sysadminweekly.com- SysAdmin Weekly Newsletter: https://newsletter.sysadminweekly.com- SysAdmin Weekly GitHub Discussions: https://github.com/ProjectRunspace/sysadmin-weekly/discussions- Project Runspace: https://www.projectrunspace.org- AndyOnTech: https://www.andyontech.com

Episode metadata supplied by the publisher feed · Published Jun 19, 2026

Embed this episode

Ready to play

049 - How Do Attackers Use Local LLMs to Phish At Scale?

0:00 1:02:21

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of SysAdmin Weekly?

This episode is 1 hour and 2 minutes long.

When was this SysAdmin Weekly episode published?

This episode was published on June 19, 2026.

Can I download this SysAdmin Weekly episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!