logo

Five Shady Phishing Email Techniques We Spotted in 2025

ID: 862eb7a1-a564-5c79-9e22-5fff3e901eca

STIX ID: report--862eb7a1-a564-5c79-9e22-5fff3e901eca

Feed Name: Huntress Blog

Date Published: 2025-12-04

Date Updated: 2026-04-28

...
...

Huntress outlines five effective phishing techniques seen this year—voicemail lures using SVG/HTML that redirect to fake Microsoft logins (often via the Raccoon0365 kit), callback phishing with bogus support numbers, brand impersonation leveraging open-redirects to attacker pages, shipping notifications employing ASCII QR codes to evade scanners, and “Living off Trusted Sites” that pivot through trusted services like Figma/Dropbox with CAPTCHA/Turnstile interstitials—highlighting obfuscation and pre-populated email tactics, and recommending awareness training, MFA, email filtering, and clear reporting processes to mitigate risk.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.