logo

New Phishing Trends and Evasion Techniques

ID: acce079d-292e-58af-8dc0-af303a434dd3

STIX ID: report--acce079d-292e-58af-8dc0-af303a434dd3

Feed Name: Zscaler Security Research Blog

Threat Score
65/100

Date Published: 2025-07-03

Date Updated: 2026-05-01

...
...

Zscaler ThreatLabz documents four active phishing campaigns that target brands like Microsoft, Chase and Dropbox by using multilayer JavaScript obfuscation (JavaScript Obfuscator, eval+/atob, hex-encoding), Base64-embedded images, and hosting on trusted services (storage.googleapis.com, *.web.app) or compromised WordPress sites to bypass analysis; the blog provides deobfuscation examples, PCAP evidence of credential exfiltration and a long list of IoCs observed in the Zscaler cloud.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.