Phishing Blog- 2026 2025 2024 2023 2021 2020 2019 2018
AI blog APT blog Attack blog BigBrother blog BotNet blog CyberCrime blog Cyber blog Cryptocurrency blog Exploit blog Hacking blog ICS blog Incident blog IoT blog Malware blog OS Blog Phishing blog Ransom blog Safety blog Security blog Social blog Spam blog Vulnerebility blog
DATE | NAME | Info | CATEG. | WEB |
|
9.9.26 |
Phishing Attacks Serve Browser-in-the-Browser Pages, Rogue RMM Persistence | Huntress recently analyzed two attacks that started with a phishing message and then redirected victims to a browser-in-the-browser (BiTB) page (both using the same template and lure) that prompted them to download an "updated Adobe Reader" version to view files. | Phishing blog | Huntress |
|
8.9.26 |
Tracking BigBear 2.0 Evilginx2 Phishing Campaign | CloudSEK researchers uncovered BigBear 2.0, a global Microsoft 365 phishing-as-a-service operation targeting hundreds of organizations across 40+ countries. | Phishing blog | CloudSEK |
|
5.9.26 |
ASCII smuggling crosses over from AI prompt injection to phishing evasion | Invisible Unicode characters popularized for hiding instructions from AI models are now being used to obfuscate words before email filters parse them. | Phishing blog | Microsoft blog |
|
3.9.26 |
Kali365 phishing kit abuses Microsoft authentication | Barracuda Networks Blog | The Kali365 phishing kit epitomizes a major shift in phishing, from stealing passwords to abusing legitimate authentication processes. | Phishing blog | BARRACUDA |
|
3.9.26 |
The Outsider Phishing Kit: A Resilient Threat in the Face of Law Enforcement Action | Group-IB Blog | This blog provides a deep-dive into the phishing kit created by Chenlun known as the Outsider Phishing Kit. It is a well established kit in the Chinese community with over 267 ready-made phishing templates targeting over 54 countries worldwide. | Phishing blog | GROUP-IB |
|
3.9.26 |
BlueKit PhaaS in the Wild: BitM, Geofencing, and ScreenConnect Post-Exploitation | The campaign did not stop at credential or session theft. After a BlueKit browser-in-the-middle flow, selected victims were moved into a fake document-viewer workflow that delivered a legitimate ScreenConnect client configured for an attacker-used ScreenConnect cloud instance. | Phishing blog | ZEROBEC BLOG |
|
2.9.26 |
Beyond Device Code Phishing: Preparing for the Next Wave of AI-Powered Attacks | Cybercriminals have always embraced new technologies to improve their effectiveness. Today, artificial intelligence has become another tool that can help threat actors operate faster and at greater scale. | Phishing blog | PROOFPOINT |
|
29.8.26 |
ZeroTokens: Phishing Platform Gives Operators Real-Time Control of Attack Flow |
ZeroTokens supports impersonation of 53 financial institution brands to collect credentials, identity data, payment details, and verification codes. |
||
|
29.8.26 |
The SOCRadar Threat Research Unit (STRU) has conducted an “inside-out” analysis of AnonyMousKIT, an AI-powered Phishing-as-a-Service (PhaaS) ecosystem specifically engineered to disable Apple’s Activation Lock on stolen devices. |
|||
| 29.8.26 | JavaScript obfuscation: From party trick to phishing kit | Learn the basics of what obfuscation is, why a researcher would try to reverse it, and several ways to approach the problem. | Phishing blog | CISCO TALOS |
| 22.8.26 | Device Code Phishing Up 1500% | In a story recently reported by Dark Reading, Crowdstrike researchers found that device code phishing and voice phishing (vishing) attacks have more than doubled as cybercriminals increasingly combine phone calls with mobile authentication workflows to trick users into approving fraudulent device authentication requests, enabling corporate network access. | Phishing blog | ZIMPERIUM |
|
22.8.26 |
Mirage2FA Hijacks Companies’ Microsoft 365 Sessions, with Over 4K Victims in the US | Mirage2FA is an active phishing-as-a-service toolkit built to steal Microsoft 365 credentials and authenticated sessions through Adversary-in-the-Middle (AiTM) attacks. | Phishing blog | ANYRUN BLOG |
|
22.8.26 |
Post-DEF CON Phishing Uses Google Doc Apps Script to Deliver Malware | Following Black Hat/DEF CON, a Huntress researcher was targeted by a threat actor who used X DMs and fake security conference planning as a pretext to establish trust before attempting to deploy malware. The researcher recognized the lure as a scam and did not fall for it, but continued engaging with the actor to better understand the tactics they were using. | Phishing blog | Huntress |
| 22.8.26 | How QR-code phishing can slip past corporate security measures | Quishing has become a popular alternative to traditional phishing. Here’s how businesses can close the gap. | Phishing blog | Eset |
|
15.8.26 |
The phishing link that died on purpose | A single expired URL exposed a phishing campaign built around Mailer-Go, Cloudflare Workers and an EvilTokens OneDrive lure. | Phishing blog | GENDIGITAL |
|
15.8.26 |
Dissecting the JWR phishing framework | Cisco Talos recently identified an undocumented phishing framework, internally branded "JWR" by its developer, built to convincingly impersonate checkout and login pages across major payment and shopping platforms. | Phishing blog | CISCO TALOS |
|
6.8.26 |
Formula 1 Phishing Campaign & Kit Analysis | SOCRadar Threat Research Unit (STRU) has identified and analyzed a sophisticated, multi-stage phishing campaign that exploits the high-intensity demand for Formula 1 Grand Prix tickets. The attackers use highly convincing replicas of official ticketing platforms to deceive victims, tricking them into providing payment information and two-factor authentication (2FA) tokens. | Phishing blog | SOCRADAR |
|
8.8.26 |
Fake Bank of America "Action Needed" Phishing Email Deposits ScreenConnect Instead | We recently came across a fake Bank of America message that closely imitates the targeted bank's visual style, layout, and branding – from the initial phishing email, to the eventual webpage that victims are redirected to. | Phishing blog | Huntress |
|
8.8.26 |
Payroll Pirates: Strange New Tides in Business Email Compromise | Key Takeaways Arctic Wolf is tracking an active, widespread email-driven phishing campaign that uses adversary-in-the-middle (AiTM) techniques to compromise Microsoft 365 accounts, identify personnel involved | Phishing blog | ARTICWOLF |
|
1.8.26 |
Operation BlueDash: Multi-RMM Workplace Phishing | ZeroBEC investigated a live Microsoft Teams-themed phishing operation that began with a "secure document" email and ended with the silent enrollment of the victim endpoint into attacker-controlled remote monitoring and management environments. | Phishing blog | ZEROBEC BLOG |
|
1.8.26 |
Kali365 Ringer: Targeting Financial and Insurance Sectors | ZeroBEC prevented a Kali365 device-code phishing attack targeting a financial, regulated customer environment. The lure used a missed-call notification and a trusted Google Sites wrapper before redirecting through Google redirector, OCI API Gateway, and a Cloudflare-protected Kali365 host. The campaign targeted multiple organizations on the same day, including financial and insurance services customers, using the same Google Sites landing page, sender subdomain, subject pattern, and fake internal reference ID. | Phishing blog | ZEROBEC BLOG |
|
1.8.26 |
Inside JIVS PhishKit: A Domain-Adaptive Credential Harvester | ZeroBEC prevented a coordinated mailbox credential-harvesting campaign targeting multiple users within the same Microsoft 365 organization. The messages used an authenticated but unrelated external sender, warned that each recipient mailbox had violated policy, and directed users to a live PHP phishing page on corychase[.]org. | Phishing blog | ZEROBEC BLOG |
|
1.8.26 |
Building Resilience Against AiTM Phishing: What SOC Leaders Should Know | Email gateways, endpoint controls, and file-centric sandboxing remain essential layers of defense. But many of today’s phishing attacks unfold in ways they weren’t designed to fully expose. | Phishing blog | ANYRUN BLOG |
|
1.8.26 |
Chaos in Teams vishing | Sophos analysts investigated a Microsoft Teams voice phishing (vishing) campaign tracked as STAC4749 that used a consistent set of IT-themed cloud domains and personas to gain remote access to victims’ systems. Between February and June 2026, Sophos analysts observed the threat actors targeting dozens of North American organizations. | Phishing blog | SOPHOS |
|
1.8.26 |
Device Code Phishing: Turning a Convenience Feature Into an MFA Bypass | Device code phishing abuses a legitimate authentication feature designed for devices with limited input capabilities. This article breaks down how the technique works, examines a recent observed case, and outlines the layered security measures organizations can implement. | Phishing blog | Trend Micro |
|
25.7.26 |
Law Enforcement Takes Down Kratos/Sneaky2FA Phishing Service, With an Assist From TrendAI™ | Kratos, the phishing-as-a-Service (PhaaS) platform behind a large share of recent Microsoft 365 credential theft, has been taken offline by the BKA and ZIT in an operation dubbed Olympus Blade. | Phishing blog | Trend Micro |
|
25.7.26 |
Device Code Phishing: Turning a Convenience Feature Into an MFA Bypass | Device code phishing abuses a legitimate authentication feature designed for devices with limited input capabilities. This article breaks down how the technique works, examines a recent observed case, and outlines the layered security measures organizations can implement. | Phishing blog | Trend Micro |
| 14.7.26 | Defending SaaS-based applications against ShinyHunters OAuth abuse | In a series of campaigns observed between mid-2025 and mid-2026, Microsoft identified threat actor activity with overlapping tradecraft commonly associated with ShinyHunters, including voice phishing (vishing), supply chain compromise, and misconfigured guest access to target customer SaaS-based applications such as Salesforce instances. The threat actors abused trusted OAuth relationships for unauthorized access, data exfiltration, and persistence. | Phishing blog | Microsoft blog |
| 11.7.26 | Phishing in the Balkans: Fake Traffic Fines, Real Losses | This blog documents Group-IB’s research into an SMS phishing campaign targeting Serbian road users through the impersonation of Serbia's state road authority, and how it can be linked to both Darcula and Phoenix PhaaS platforms with victims across the globe. | Phishing blog | GROUP-IB |
| 11.7.26 | From Invoice to AnyDesk: Uncovering a Phishing Campaign Targeting Russian Aerospace Organizations | Table of Contents Introduction Infection Chain Technical Analysis Conclusion Seqrite Coverage Indicators of Compromise (IOCs) MITRE ATT&CK Mapping Introduction The Seqrite Threat Research Team identified a targeted spear-phishing campaign disguised as a legitimate business invoice. The phishing email impersonates a legitimate... | Phishing blog | Seqrite |
| 4.7.26 | ARToken: Inside an EvilTokens affiliate panel targeting Microsoft 365 | Talos has identified "ARToken," a phishing-as-a-service platform that targets Microsoft 365. The ARToken panel exposes 80+ API endpoints for device code phishing, Primary Refresh Token persistence, email access, BEC operations, and SharePoint exfiltration. | Phishing blog | CISCO TALOS |
| 30.5.26 | In late 2025, Mandiant responded to a security incident involving a compromised web server running KnowledgeDeliver. KnowledgeDeliver is a Learning Management System (LMS) developed by Digital Knowledge commonly used in Japan. Mandiant identified a critical vulnerability that allowed unauthenticated Remote Code Execution (RCE). | Phishing blog | GTI | |
| 23.5.26 | Google Threat Intelligence Group (GTIG) has continued to track an expansive extortion campaign by UNC6671, a threat actor operating under the "BlackFile" brand, that targets organizations via sophisticated voice phishing (vishing) and single sign-on (SSO) compromise. | Phishing blog | GTI | |
| 9.5.26 | Breaking the code: Multi-stage ‘code of conduct’ phishing campaign leads to AiTM token compromise | Microsoft Defender Research observed a large-scale credential theft campaign that exemplifies this trend, using code of conduct-themed lures, a multi-step attack chain, and legitimate email services to distribute fully authenticated messages from attacker-controlled domains. | Phishing blog | Microsoft blog |
| 25.4.26 | Phishing and MFA exploitation: Targeting the keys to the kingdom | In 2025, attackers increasingly targeted weaknesses in multi-factor authentication (MFA) workflows, and phishing attacks leveraged valid, compromised credentials to launch lures from trusted accounts. The trends focused entirely on trust, or the lack thereof, in everyday business operations. | Phishing blog | CISCO TALOS |
| 18.4.26 | The n8n n8mare: How threat actors are misusing AI workflow automation | Cisco Talos research has uncovered agentic AI workflow automation platform abuse in emails. Recently, we identified an increase in the number of emails that abuse n8n, one of these platforms, from as early as October 2025 through March 2026. | Phishing blog | CISCO TALOS |
| 11.4.26 | The Trojan horse of cybercrime: Weaponizing SaaS notification pipelines | Cisco Talos has recently observed an increase in activity that is leveraging notification pipelines in popular collaboration platforms to deliver spam and phishing emails. | Phishing blog | CISCO TALOS |
| 28.3.26 | When tax season becomes cyberattack season: Phishing and malware campaigns using tax-related lures | During tax season, threat actors reliably take advantage of the urgency and familiarity of time-sensitive emails, including refund notices, payroll forms, filing reminders, and requests from tax professionals, to push malicious attachments, links, or QR codes. | Phishing blog | Microsoft blog |
| 7.3.26 | Inside Tycoon2FA: How a leading AiTM phishing kit operated at scale | Tycoon2FA has become a leading phishing-as-a-service (PhaaS) platforms, enabling campaigns that reach over 500,000 organizations monthly, prompting Microsoft’s Digital Crimes Unit (DCU) to work with Europol and industry partners to facilitate a disruption of Tycoon2FA’s infrastructure and operations. | Phishing blog | Microsoft blog |
| 7.3.26 | Europol, Microsoft, TrendAI™ and Collaborators Halt Tycoon 2FA Operations | Tycoon 2FA was dismantled this week by law enforcement and industry partners including TrendAI™. The phishing-as-a-service platform offered MFA bypass services using adversary-in-the-middle (AitM) proxying. | Phishing blog | Trend Micro |
| 21.2.26 | Phishing on the Edge of the Web and Mobile Using QR Codes | This article explores the misuse of QR codes in today's threat landscape, covering three areas of concern: | Phishing blog | Palo Alto |
| 7.2.2026 | Why Smart People Fall For Phishing Attacks | The cybersecurity landscape of 2026 is stronger than ever with countless security resources and protective tools. Despite robust defenses at anyone’s fingertips, common phishing scams and spoofing attacks remain an ongoing issue. Unfortunately, the reality is that these attacks aren’t disappearing; they’re simply evolving. | Phishing blog | Palo Alto |
| 7.2.2026 | Cybereason TTP Briefing Q4 2025: Diverse Phishing Tactics and RATs on the Rise | Explore the most effective trends, techniques, and procedures used by threat actors in Q4 2025, with frontline threat intelligence from our incident response experts. | Phishing blog | Cybereason |
| 1.2.26 | Special Alert: SLSH Malicious "Supergroup" Targeting 100+ Organizations via Live Phishing Panels | A massive identity-theft campaign is currently active, targeting Okta Single Sign-On (SSO) and other SSO platform accounts across 100+ high-value enterprises. | Phishing blog | Silent Push |
| 24.1.26 | The Next Frontier of Runtime Assembly Attacks: Leveraging LLMs to Generate Phishing JavaScript in Real Time | Imagine visiting a webpage that looks perfectly safe. It has no malicious code, no suspicious links. Yet, within seconds, it transforms into a personalized phishing page. | Phishing blog | Palo Alto |
| 17.1.26 | In Q4 2025, Microsoft once again ranked as the most impersonated brand in phishing attacks, ... | Phishing blog | CHECKPOINT | |
| 17.1.26 | Ransomware and Supply Chain Attacks Soared in 2025 | The threat landscape shifted significantly in 2025. Here are the threats and trends to watch as we enter 2026. | Phishing blog | |
| 17.1.26 | Mamba Phishing-as-a-Service Kit: How Modern adversary-in-the-middle (AiTM) Attacks Operate | INTRODUCTION CYFIRMA assesses that Mamba 2FA is a representative of a broader class of adversary-in-the-middle phishing frameworks that have become increasingly prevalen | Phishing blog | |
| 17.1.26 | The Unfriending Truth: How to Spot a Facebook Phishing Scam Before It's Too Late | In the second half of 2025, Trellix observed a surge in credential-stealing Facebook phishing scams, particularly those using the sophisticated "Browser in the Browser" (BitB) technique to trick users with fake login pop-ups. | Phishing blog | Trelix |
| 10.1.26 | Beyond MFA: Identity Abuse Through Token Interception and Consent Manipulation | EXECUTIVE SUMMARY Multi-Factor Authentication (MFA) has long been positioned as a definitive control against credential-based attacks. However, recent phishing campaigns | Phishing blog | |
| 10.1.26 | Phishing actors exploit complex routing and misconfigurations to spoof domains | Threat actors are exploiting complex routing scenarios and misconfigured spoof protections to send spoofed phishing emails, crafted to appear as internally sent messages. | Phishing blog | Microsoft blog |