Quick Summary
The Securityish Brief
Email remains a primary entry point for attackers, with security teams managing high volumes of malicious messages that vary across campaigns. In 2025, Cofense research revealed that one malicious email was identified on average every 19 seconds. Attackers leverage AI to generate, test, and deploy phishing campaigns, complicating detection efforts as traditional tools struggle to keep pace with the variations in emails, links, and files.
Phishing pages are adapting based on the visitor’s device, delivering different payloads depending on the operating system or browser type. For example, Windows users may receive executable malware, while macOS users encounter platform-specific packages. The rise of Android-focused delivery in 2025 surpassed activity from the previous three years combined, indicating a shift in targeting strategies.
Credential phishing campaigns are increasingly sophisticated, gathering detailed visitor information such as browser plugins and geographic location to customize page rendering and payload selection. During 2025, 76 percent of initial infection URLs appeared only once across customer environments, indicating a trend toward polymorphism where each message or file appears unique despite being part of the same campaign.
Conversational attacks, which accounted for 18 percent of identified malicious emails in 2025, rely on simple dialogue rather than links or attachments. These messages often impersonate executives or vendors, using AI-generated language to improve context and tone, making them harder to distinguish from legitimate communications.
Attackers are also abusing legitimate remote access tools, which saw a more than 100 percent increase in reported activity year over year. These tools blend into standard administrative traffic, complicating detection and response efforts.
Credential phishing campaigns have shifted toward less common top-level domains, such as .es, which have surged in usage for credential theft activities. This trend is accompanied by the use of generic and automated subdomains, indicating large-scale deployment through phishing kits.
Understanding the Evolving Threat Landscape
AI’s role in phishing has fundamentally changed the effectiveness of these attacks, allowing threat actors to craft highly personalized emails and dynamically adapt phishing pages based on the victim’s device. Organizations must recognize that traditional email security tools may not adequately protect against these evolving threats.
Key Takeaways
- Regularly update email security tools to enhance detection of evolving phishing tactics.
- Educate employees on recognizing conversational attacks and the importance of verifying requests from executives or vendors.
- Monitor for unusual activity related to remote access tools and ensure they are used appropriately within your organization.
- Implement multi-factor authentication to add an extra layer of security against credential theft.
- Review and update policies regarding the use of less common top-level domains in communications.
Key Terms & Concepts
- Polymorphism: In this article, polymorphism refers to the practice of making each phishing message or file appear unique even when part of the same campaign.
- Credential phishing: Credential phishing is a type of attack where attackers attempt to steal user credentials by mimicking legitimate login pages.
- Conversational attacks: Conversational attacks are phishing attempts that rely on dialogue rather than links or attachments, often impersonating trusted individuals.
- Remote access tools: Remote access tools are legitimate software used for IT support that attackers exploit to maintain control over compromised systems.
Your 5-Minute Securityish Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.
Securityish
Securityish explains cybersecurity, scams, data breaches, and privacy risks in simple language so you know what’s happening and how to protect yourself.
Navigation
Your 5-Minute Cybersecurity Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.