Cybercriminals are increasingly utilizing advanced Phishing-as-a-Service (PhaaS) kits to conduct large-scale, targeted phishing campaigns that impersonate trusted brands and institutions. These kits, which have doubled in number over the past year, enable even less-skilled attackers to deploy sophisticated attacks at scale by incorporating features such as URL obfuscation, MFA bypass, CAPTCHA abuse, and the use of malicious QR codes and attachments. Threat analysts have observed a surge in new PhaaS entrants, including Cephas, Whisper 2FA, and GhostFrame, alongside established kits like Tycoon 2FA and Mamba 2FA. Attackers are also leveraging AI, social engineering, and polymorphic techniques to evade detection, making it increasingly difficult for organizations to defend against these threats with static security controls alone.
Technical analysis reveals that phishing infrastructure is evolving to include fake verification pages, such as counterfeit Cloudflare Turnstile challenges, which act as intelligent traffic filtering gates. These pages use browser fingerprinting, geolocation, and proxy detection to selectively deliver malicious payloads to high-confidence victims while evading security researchers and automated defenses. The fake verification pages closely mimic legitimate branding and user experience, including fabricated Ray IDs and links to real policy documents, to build trust and bypass scrutiny. Security experts recommend adopting layered defenses, including phishing-resistant MFA, continuous monitoring, and integrated email security, to counter these increasingly sophisticated phishing operations.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
Analysis showed the fake verification page did not load official Cloudflare JavaScript and instead used client-side scripts and server-side APIs to collect browser and environment data for exfiltration. Researchers confirmed the infrastructure functioned as a malicious traffic distribution system and was not affiliated with Cloudflare.
Researchers observed a phishing campaign using a fake Cloudflare Turnstile page as an intelligent traffic filtering gate targeting French users. The infrastructure used browser fingerprinting, geolocation, proxy detection, and redirects to a legitimate French news site to block researchers and non-target traffic while serving phishing content to likely victims.
The phishing infrastructure analyzed in the campaign relied on newly registered domains used to host a fake Cloudflare Turnstile verification page and related backend services. The setup was designed to support selective victim filtering and payload delivery.
Throughout 2025, phishing kits were observed using AI, URL obfuscation, CAPTCHA abuse, malicious QR codes, and polymorphic techniques to improve delivery and evade detection. Named kits including Tycoon 2FA, Mamba 2FA, Cephas, Whisper 2FA, GhostFrame, Sneaky 2FA, and CoGUI were cited as examples of this trend.
Barracuda Networks reported that the number of active phishing-as-a-service kits doubled in 2025, reflecting broader criminal adoption of more capable phishing tooling. The kits increasingly incorporated MFA bypass, evasion features, and abuse of trusted platforms.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
socradar.io
Open sourcehelpnetsecurity.com
Open sourcemalwr-analysis.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.