Threat actors are increasingly adopting sophisticated email phishing techniques that leverage both established and novel methods to bypass security controls and deceive users. One prominent trend is the use of PDF attachments in phishing emails, where attackers embed QR codes within the PDF files. This tactic encourages recipients to scan the QR code with their mobile devices, which often lack the robust security protections of corporate endpoints, thereby increasing the likelihood of successful credential theft or malware installation. In addition to QR codes, attackers are also distributing password-protected PDF attachments. The passwords are either included in the email or sent separately, which not only complicates automated scanning by security solutions but also lends an air of legitimacy to the communication, making recipients more likely to trust and open the files. These methods represent a resurgence and refinement of older phishing tactics, demonstrating the adaptability of threat actors in response to evolving security measures. Another significant development is the deployment of SVG image attachments as phishing lures, as seen in the Tykit phishing kit. This kit, identified as part of a phishing-as-a-service (PhaaS) operation, uses SVG files that mimic secure document viewers or prompt users to enter information, such as the last four digits of their phone number, under the guise of accessing secure content. The SVG files contain embedded JavaScript that redirects victims through a series of intermediary pages, ultimately leading to a fake Microsoft 365 login page designed to harvest credentials. The infrastructure supporting these attacks is highly organized, with command-and-control (C2) servers identified by unique URL patterns and attack flows that include adversary-in-the-middle (AitM) techniques to intercept and replay stolen credentials. The Tykit campaign has targeted hundreds of victims across multiple sectors, including finance, IT, government, professional services, and construction, with a notable concentration in the United States, Canada, and Southeast Asia. Activity associated with this campaign peaked in the latter half of 2025, indicating a surge in the adoption of these advanced phishing methods. The use of both PDF and SVG attachments in phishing campaigns highlights the ongoing arms race between attackers and defenders, as threat actors continuously refine their techniques to evade detection and exploit user trust. Security teams are challenged to adapt their defenses to account for encrypted attachments, QR code-based lures, and sophisticated image-based phishing kits. The prevalence of phishing-as-a-service offerings further lowers the barrier to entry for cybercriminals, enabling widespread and coordinated attacks. Organizations are urged to enhance user awareness, implement advanced email filtering, and monitor for emerging phishing tactics that leverage non-traditional attachment types and multi-stage attack chains. The evolving landscape of email phishing underscores the need for a multi-layered security approach that addresses both technical and human vulnerabilities.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
SC Media reported on the Tykit SVG phishing kit and linked it to attacks aimed at stealing Microsoft 365 credentials. With no earlier incident date provided in the reference, the publication date is used as the event date.
Kaspersky Securelist published an analysis describing how threat actors are reusing and refining established email phishing methods, framing it as part of the 2025 phishing landscape. The reference is a trend report rather than a single incident, so the publication date is used as the event date.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.