In 2025, phishing attacks increasingly used omni-channel methods, bypassing traditional email filters by exploiting social media, search engines, and malvertising channels. Attackers also used advanced tools like Phishing-as-a-Service kits and sophisticated evasion techniques to evade detection and bypass security controls. #ScatteredLapsus$Hunters #Evilginx #PushSecurity
Keypoints
- Phishing attacks in 2025 expanded beyond email to platforms like LinkedIn and Google Search.
- Non-email channels offer attackers less security screening and higher engagement with targets.
- Criminal PhaaS kits facilitate sophisticated, MFA-bypassing phishing campaigns, enabling lower entry barriers for cybercriminals.
- Attackers develop evasion techniques such as redirect chains, client-side JavaScript loading, and bot protection to hide malicious activity.
- Security teams must enhance browser-based detection and response capabilities to close visibility gaps and combat modern phishing threats.