Generative AI-based threats have spurred a 140% year-on-year increase in browser-based phishing attacks, according to the latest research from Menlo Threat Intelligence.
In its latest State of Browser Security report, the cybersecurity firm identified more than 752,500 browser-based phishing attacks, while also noting more than 170,000 zero-hour phishing attacks over the last 12 months, a 130% increase from 2023.
According to Menlo, genAI threats began to surge over the last year with nearly 600 incidents of genAI imposter sites being used to manipulate and exploit unsuspecting victims, with cybercriminals creating nearly one million phishing sites per month by H2 2024, a nearly 700% increase since 2020.
Digging further into the data, the report found a notable rise in zero-day vulnerabilities affecting both Chrome and Edge browsers, with the threat of in-browser credential phishing growing, and an average window of exposure stretching to six days before legacy security tools can detect zero-hours phishing attacks.
Traditional security tools are struggling to keep pace with the rapidly evolving landscape, evident by the one in five attacks Menlo detected displaying some form of evasive technique designed to evade traditional network and endpoint-based security controls.
The study also found a 104% increase in the abuse of Cloudflare domains for phishing attempts, with these platforms being particularly attractive to cybercriminals because they offer free hosting, legitimate appearances, and the ability to bypass security filters, with attackers able to host phishing pages and malware, as well as redirect users to fake login pages.
Even more worrying is the rise in abusive cloud hosting sites, with cybercriminals exploiting cloud services to host malicious content, such as phishing sites, ransomware, and command-and-control (C2) infrastructure.
Menlo said that with cloud providers less likely to monitor for harmful activities than traditional hosting services, cybercriminals can hide in plain sight and move quickly to deploy their attacks at scale, all while remaining anonymous, making these abusive cloud hosts especially dangerous for enterprises.
Recommended reading
- ‘Big Game’ Ransomware Tactics Drives Spike in Attacks
- Is Automation Fuelling a New Era of Cyber-crime?
- Phishing Attacks Spiked in 2024 As Other Cyber-threats Declined
“As we enter 2025, cybercriminals are expected to adopt more sophisticated and specialised tactics, with a focus on more targeted and impactful attacks,” concludes the report.
“Anticipated trends include the rise of cybercrime groups and more elaborate PhaaS kits specialising in specific attack-chain segments, allowing for more precise and efficient exploitation.
“Cloud environments will become an even greater focal point for adversaries, as attackers target cloud-specific vulnerabilities amid the growing reliance on multiple cloud providers.
“Additionally, the proliferation of automated hacking tools on dark web marketplaces will expand, with browser-based phishing kits and Ransomware-as-a-Service(RaaS) becoming more prevalent.”





