The idea that social engineering, or phishing as it’s now known, is perpetrated by lone players impersonating a Nigerian Prince has long since been blown to bits by the reality of modern-day cybercrime. Determined cybercriminals now rely on phishing-as-a-service platforms, phishing kits if you prefer, to execute their attacks. Phishing kits that doubled in number across the course of the last year.
That’s according to the Barracuda 2025 phishing review, which confirmed that an astonishing 90% of โhigh-volume phishing campaignsโ were executed with the help of phishing kits. Which is problematic as it touches on the Nigerian Prince quandary: unskilled threat actors canโt get away with that kind of simple ruse anymore, but they can use phishing kits to deploy complex and convincing attacks.
As the Barracuda report said, these kits enable them to โaccess advanced tools and automation and launch large-scale, targeted phishing campaigns, often impersonating legitimate services and institutionsโ.
New, improved phishing kits
The phishing kit landscape is littered with new entrants, including the likes of โaggressive newcomers such as Whisper 2FA and GhostFrameโ. These, the report revealed, โintroduced inventive and evasive tools and tactics, including a suite of techniques to prevent analysis of their malicious codeโ.
Established players, such as Mamba and Tycoon, have continued to evolve their platforms and continue to thrive in this increasingly cutthroat business. The Mamba platform, for example, was used in 10 million 2FA-bypassing attacks in late 2025 alone.
Most worrying, however, is that despite the continuing advances in the sophistication of these platforms – from both the detection-avoidance perspective and their capability to bypass multifactor authentication – at the most basic level nothing has changed when it comes to phishing attacks.
Phishing patterns stay the same
The most common โluresโ used continue to be fake payment, financial, legal, digital signature and HR-related messages. The most common โactionโ continues to be link clicking, QR code scanning and attachment opening. The most commonly spoofed burdens continue to be Microsoft, DocuSign and SharePoint.
โTo stay protected,โ said Ashok Sakthivel, Director of Software Engineering at Barracuda, โorganisations need to move past static defences and adopt layered strategies: user training, phishing-resistant MFA, continuous monitoring, and to ensure email security sits at the heart of an integrated, end-to-end security strategy.โ
With threat actors increasingly relying upon AI to craft convincing attack messaging and advances in security bypass and obfuscation techniques, you can’t afford to ignore Sakthivelโs message in 2026.
Related articles