Based on the status quo of email technology development,this paper summarizes and reviews the overall situation and hidden risks of email security in China.From the perspective of social engineering,it studies the methods,types and application techniques of mainstream phishing email attacks in recent years,and introduces the working principles of malicious Trojan horse,self-extracting file and dynamic link library side loading and other attack techniques commonly used in malicious attachments to emails.This paper analyzes the risks and hidden dangers of phishing email attacks aggravated by new information technologies such as generative AI robot and multi-fragment program coding confusion,and puts forward countermeasures and suggestions on how to prevent and deal with the new phishing email attacks based on theory and reality.