Phishing kits became significantly more prevalent and sophisticated during 2025, as cyber-criminals increasingly relied on Phishing-as-a-Service platforms to scale attacks and bypass modern security controls, according to analysis from Barracuda threat researchers.
The firm said the number of known phishing kits doubled over the course of the year, with new entrants arriving equipped with advanced evasion techniques, stealth deployment methods and multifactor authentication bypass capabilities.
By the end of 2025, 90% of high-volume phishing campaigns were leveraging PhaaS kits, enabling even less-skilled attackers to launch large-scale, targeted campaigns impersonating legitimate services and institutions.
Top PhaaS attack themes
Barracuda said in the Threat Spotlight that the most common phishing themes seen during 2025 remained worryingly familiar. Campaigns frequently centred on fake payment and invoice requests, financial and legal documents, digital signature notifications and HR-related messages. These emails were designed to trick recipients into clicking links, scanning QR codes or opening attachments and sharing personal information.
Despite increased user awareness and improving email security, these long-established techniques continued to succeed by spoofing trusted brands such as Microsoft, DocuSign and SharePoint. Barracuda attributed this success to continuous innovation in the underlying tools and tactics, with attackers making emails appear increasingly authentic and convincing.
Payment and invoice scams evolved through the use of generative AI to produce highly realistic overdue payment notifications that closely matched the tone, branding and language of legitimate services. QR codes were commonly embedded in invoices to shift victims from more secure desktop environments to less protected mobile devices.
Voicemail-based phishing campaigns, or vishing, included links to fake secure voicemail portals designed to harvest credentials. Generative AI was used to produce multiple email variations to bypass detection, while spoofed sender addresses and familiar notification designs were used to increase credibility.
Financial and legal document scams combined social engineering with generative AI to remove errors and personalise messages. In many cases, attackers researched organisations in detail and impersonated senior executives, sometimes using compromised email accounts to pressure staff into approving fraudulent transfers.
Signature and document review scams impersonated an expanding range of trusted platforms, using urgent language and QR codes to move attacks outside corporate security perimeters. HR-related phishing campaigns were timed to coincide with payroll cycles and tax deadlines, embedding QR codes in policy updates to bypass email filtering.
Popular techniques used in phishing in 2025
Barracuda said phishing kits used a wide range of technical techniques throughout 2025. URL obfuscation methods designed to evade detection appeared in nearly half of all attacks, often combined with open redirects and human verification steps to make malicious links appear legitimate. MFA bypass techniques, including session cookie theft, were also observed in nearly half of campaigns.
CAPTCHA abuse featured in more than 40% of attacks, adding perceived legitimacy while hiding malicious destinations. QR-code-based attacks accounted for a growing proportion of campaigns, with attackers splitting QR codes into multiple images or nesting malicious codes within legitimate ones to evade detection.
Polymorphic attacks varied email headers, content and destinations to delay detection, while malicious attachments and abuse of trusted online platforms remained common.
Attackers also increasingly leveraged generative AI, including no-code platforms, AI-generated CAPTCHA content and automatically generated comments and code. More niche techniques included the use of Blob URIs to store data in memory, making attacks harder to detect, and ClickFix social engineering methods that trick victims into manually executing malicious commands.
Phishing kits doubled in number as newcomers moved in
Barracuda reported a doubling in the number of PhaaS kits in active use during 2025. Established kits such as Tycoon 2FA and Mamba 2FA faced growing competition from newer entrants including Cephas, Whisper 2FA and GhostFrame, many of which demonstrated a strong focus on stealth, MFA bypass and anti-analysis capabilities.
Sneaky 2FA emerged as an advanced phishing kit using adversary-in-the-middle techniques to bypass two-factor authentication. The kit interacts directly with legitimate Microsoft APIs to validate captured credentials and session tokens, includes anti-bot and anti-analysis features, and uses browser-in-the-browser techniques to hide malicious URLs. Victims are redirected to Microsoft-related Wikipedia pages after credential capture to reduce suspicion.
CoGUI was observed primarily among Chinese-speaking threat actors and employed advanced evasion techniques including geofencing, header fencing and device fingerprinting. Unlike many modern kits, CoGUI did not capture MFA credentials but frequently impersonated platforms such as Amazon, PayPal, Rakuten and Apple.
Cephas relied on heavy JavaScript obfuscation and Microsoft API integration to ensure credentials and session tokens were immediately usable. Whisper 2FA prioritised speed and simplicity, using lightweight AJAX-based exfiltration and multiple layers of obfuscation alongside MFA bypass capabilities.
GhostFrame, first identified by Barracuda in September 2025, used a two-stage iframe-based attack combined with dynamic subdomain generation and blob image streaming to conceal phishing content and evade detection.
Barracuda said 2025 saw a sharp increase in the number and sophistication of phishing kits, creating a more crowded and complex threat landscape for defenders. While new kits are evolving rapidly, established tools remain highly effective. In late 2025 alone, the Mamba 2FA phishing kit accounted for close to 10 million attacks.
Beyond this, the Threat Spotlight said traditional defensive approaches are no longer sufficient and urged organisations to strengthen both technical controls and security culture as phishing techniques continue to evolve into 2026.





