Phishing kits double in number – but tactics, and defence strategies, remain the same

The idea that social engineering, or phishing as it’s now known, is perpetrated by lone players impersonating a Nigerian Prince has long since been blown to bits by the reality of modern-day cybercrime. Determined cybercriminals now rely on phishing-as-a-service platforms, phishing kits if you prefer, to execute their attacks. Phishing kits that doubled in number across the course of the last year.

That’s according to the Barracuda 2025 phishing review, which confirmed that an astonishing 90% of โ€œhigh-volume phishing campaignsโ€ were executed with the help of phishing kits. Which is problematic as it touches on the Nigerian Prince quandary: unskilled threat actors canโ€™t get away with that kind of simple ruse anymore, but they can use phishing kits to deploy complex and convincing attacks.

As the Barracuda report said, these kits enable them to โ€œaccess advanced tools and automation and launch large-scale, targeted phishing campaigns, often impersonating legitimate services and institutionsโ€.

New, improved phishing kits

The phishing kit landscape is littered with new entrants, including the likes of โ€œaggressive newcomers such as Whisper 2FA and GhostFrameโ€. These, the report revealed, โ€œintroduced inventive and evasive tools and tactics, including a suite of techniques to prevent analysis of their malicious codeโ€.

Established players, such as Mamba and Tycoon, have continued to evolve their platforms and continue to thrive in this increasingly cutthroat business. The Mamba platform, for example, was used in 10 million 2FA-bypassing attacks in late 2025 alone.

Most worrying, however, is that despite the continuing advances in the sophistication of these platforms – from both the detection-avoidance perspective and their capability to bypass multifactor authentication – at the most basic level nothing has changed when it comes to phishing attacks.

Phishing patterns stay the same

The most common โ€œluresโ€ used continue to be fake payment, financial, legal, digital signature and HR-related messages. The most common โ€œactionโ€ continues to be link clicking, QR code scanning and attachment opening. The most commonly spoofed burdens continue to be Microsoft, DocuSign and SharePoint.

โ€œTo stay protected,โ€ said Ashok Sakthivel, Director of Software Engineering at Barracuda, โ€œorganisations need to move past static defences and adopt layered strategies: user training, phishing-resistant MFA, continuous monitoring, and to ensure email security sits at the heart of an integrated, end-to-end security strategy.โ€

With threat actors increasingly relying upon AI to craft convincing attack messaging and advances in security bypass and obfuscation techniques, you can’t afford to ignore Sakthivelโ€™s message in 2026.

Avatar photo
Davey Winder

With four decades of experience, Davey is one of the UK's most respected cybersecurity writers and a contributing editor to PC Pro magazine. He is also a senior contributor at Forbes. You can find him at TechFinitive covering all things cybersecurity.