GhostFrame phishing kit fuels widespread attacks against millions
ID: 0d9b308d-f806-5c28-a196-6fec609a5048
STIX ID: report--0d9b308d-f806-5c28-a196-6fec609a5048
Feed Name: Malwarebytes Blog
GhostFrame is a phishing-as-a-service (PhaaS) observed since September 2025 that has powered more than one million phishing attempts by embedding fake login screens inside iframes served from rapidly rotating subdomains and using anti-analysis techniques (disabling right-click, blocking shortcuts, tampering with developer tools). The kit hides credential collection inside image/streaming or large-file handlers to evade static scanners and spoofs legitimate brands via page titles and favicons; recommended mitigations include password managers, multi-factor authentication, cautious handling of unsolicited links, and browser-based phishing protection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
