Site navigation

Zero-Hour Phishing Attacks Up 130% Last Year

Tom Quinn

,

Browser-based phishing
Zero-day browser vulnerabilities along with a rise in the abuse of legitimate services to host phishing attacks is allowing attackers to launch sophisticated browser-based attacks.

Generative AI-based threats have spurred a 140% year-on-year increase in browser-based phishing attacks, according to the latest research from Menlo Threat Intelligence.

In its latest State of Browser Security report, the cybersecurity firm identified more than 752,500 browser-based phishing attacks, while also noting more than 170,000 zero-hour phishing attacks over the last 12 months, a 130% increase from 2023.

According to Menlo, genAI threats began to surge over the last year with nearly 600 incidents of genAI imposter sites being used to manipulate and exploit unsuspecting victims, with cybercriminals creating nearly one million phishing sites per month by H2 2024, a nearly 700% increase since 2020.

Digging further into the data, the report found a notable rise in zero-day vulnerabilities affecting both Chrome and Edge browsers, with the threat of in-browser credential phishing growing, and an average window of exposure stretching to six days before legacy security tools can detect zero-hours phishing attacks.

Traditional security tools are struggling to keep pace with the rapidly evolving landscape, evident by the one in five attacks Menlo detected displaying some form of evasive technique designed to evade traditional network and endpoint-based security controls.

The study also found a 104% increase in the abuse of Cloudflare domains for phishing attempts, with these platforms being particularly attractive to cybercriminals because they offer free hosting, legitimate appearances, and the ability to bypass security filters, with attackers able to host phishing pages and malware, as well as redirect users to fake login pages.

Even more worrying is the rise in abusive cloud hosting sites, with cybercriminals exploiting cloud services to host malicious content, such as phishing sites, ransomware, and command-and-control (C2) infrastructure.

Menlo said that with cloud providers less likely to monitor for harmful activities than traditional hosting services, cybercriminals can hide in plain sight and move quickly to deploy their attacks at scale, all while remaining anonymous, making these abusive cloud hosts especially dangerous for enterprises.


Recommended reading


“As we enter 2025, cybercriminals are expected to adopt more sophisticated and specialised tactics, with a focus on more targeted and impactful attacks,” concludes the report.

“Anticipated trends include the rise of cybercrime groups and more elaborate PhaaS kits specialising in specific attack-chain segments, allowing for more precise and efficient exploitation. 

“Cloud environments will become an even greater focal point for adversaries, as attackers target cloud-specific vulnerabilities amid the growing reliance on multiple cloud providers. 

“Additionally, the proliferation of automated hacking tools on dark web marketplaces will expand, with browser-based phishing kits and Ransomware-as-a-Service(RaaS) becoming more prevalent.”

Tom Quinn

Staff Writer, DIGIT

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data