Report by Barracuda

Threat Spotlight: How phishing kits evolved in 2025

13 FINDINGSPublished Jan 7, 2026
View Original Report →

Key Findings

In 2025, attacks bypassing multifactor authentication (MFA) were reported in 48% of phishing attacks.

BarracudaThreat Spotlight: How phishing kits evolved in 2025·Jan 7, 2026
PhishingMFAMFA BypassPhishing Techniques

In 2025, malicious QR codes were observed in 19% of phishing attacks.

BarracudaThreat Spotlight: How phishing kits evolved in 2025·Jan 7, 2026
PhishingQR CodesPhishing Techniques

In 2025, obfuscations to hide URLs from detection were seen in 48% of phishing attacks.

BarracudaThreat Spotlight: How phishing kits evolved in 2025·Jan 7, 2026
PhishingPhishing TechniquesObfuscationPhishind Detection

The number of known phishing kits doubled during 2025, reaching a significant increase in active use.

BarracudaThreat Spotlight: How phishing kits evolved in 2025·Jan 7, 2026
PhishingPhishing Kits

In 2025, 'ClickFix' social engineering techniques were used in 1% of phishing attacks.

BarracudaThreat Spotlight: How phishing kits evolved in 2025·Jan 7, 2026
PhishingPhishing TechniquesSocial EngineeringClickFix

In 2025, 90% of high-volume phishing campaigns utilized Phishing-as-a-Service (PhaaS) kits.

BarracudaThreat Spotlight: How phishing kits evolved in 2025·Jan 7, 2026
PhishingPhishing KitsPhishing-as-a-Service

In late 2025, there were 10 million Mamba 2FA phishing attacks recorded.

BarracudaThreat Spotlight: How phishing kits evolved in 2025·Jan 7, 2026
Phishing2FA

In 2025, malicious attachments were present in 18% of phishing attacks.

BarracudaThreat Spotlight: How phishing kits evolved in 2025·Jan 7, 2026
PhishingMalwarePhishing Techniques

In 2025, the abuse of trusted, legitimate online platforms was noted in 10% of phishing attacks.

BarracudaThreat Spotlight: How phishing kits evolved in 2025·Jan 7, 2026
PhishingPhishing Techniques

In 2025, the use of 'Blob URIs' was noted in 2% of phishing attacks.

BarracudaThreat Spotlight: How phishing kits evolved in 2025·Jan 7, 2026
PhishingPhishing Techniques

In 2025, attacks leveraging generative AI were reported in 10% of phishing attacks.

BarracudaThreat Spotlight: How phishing kits evolved in 2025·Jan 7, 2026
PhishingGenerative AI

In 2025, CAPTCHA was leveraged for added authenticity in 43% of phishing attacks.

BarracudaThreat Spotlight: How phishing kits evolved in 2025·Jan 7, 2026
PhishingPhishing TechniquesCAPTCHA

In 2025, 'polymorphic' attacks that varied the email header, body, and destination were seen in 20% of phishing attacks.

BarracudaThreat Spotlight: How phishing kits evolved in 2025·Jan 7, 2026
PhishingPhishing TechniquesPolymorphic