Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Phishing - Surge in Gen AI-based Threats Stimulates 140% Increase in Browser-based Phishing Attacks
Phishing Attacks News & Analysis Study & Research

Surge in Gen AI-based Threats Stimulates 140% Increase in Browser-based Phishing Attacks

Adam ParlettBy Adam ParlettMarch 27, 20254 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Browser
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

The latest annual Menlo Security State of Browser Security Report recorded a massive jump in browser-based phishing attacks and zero-hour phishing attacks in 2024. 

Over the last 12 months, they identified more than 752,500 browser-based phishing attacks against over 800 enterprises. Delving into the report, the increase from 2023, a staggering 140% in browser-based phishing attacks and a 130% in zero-hour phishing attacks specifically is largely attributable to the proliferation of Generative AI (Gen AI) for nefarious purposes. 

Just Browsing 

Browsers act as a gateway to the internet in our personal and professional lives. When people find a browser they trust, it becomes their go-to, and familiarity breeds trust; trust that cybercriminals are always looking to exploit. The report cites how 80% of the 98% of attacks originating from internet usage targeted end-user browsers. 

Some of the common attack methods are: 

Malvertising 

Using malicious adverts or ‘malvertising’ refers to when harmful code is injected into legitimate websites and advertising networks to spread malware and redirect users to harmful locations in order to steal users’ credentials. 

Exploitation of Browser Vulnerabilities 

Zero-hour browser flaws are security vulnerabilities in web browsers, such as Chrome for example, unknown to developers and users. No patches or fixes are available immediately upon discovery, providing attackers with a window to exploit them before the issue is resolved. The report identified, on average, a 6-day window of exposure before legacy tools could detect this type of threat. 

Browser-based Phishing 

Browser-based phishing attacks see bad actors create fake login pages impersonating popular and trusted organizations. The report found that 75% of phishing links are now hosted on trusted domains, including major cloud services like AWS and Cloudflare. 

Flattering to Deceive 

Microsoft, Facebook, and Netflix were the three brands found to be most impersonated in browser-based phishing attempts, with Microsoft at the top of that list. Menlo found that just under 51% of browser-based phishing attacks involved brand impersonation to varying degrees. 

The increasingly common utilization of Gen AI is reflected in the report’s detection of almost 600 incidents of fraudulent Gen AI sites. These sites were passing themselves off as Gen AI sites purporting to offer legitimate services. 

By the second half of 2024, Menlo was seeing cybercriminals create nearly one million phishing sites per month, representing a growth of almost 700% since 2020. Large language models (LLMs), a prominent subset of Gen AI, are being increasingly utilized by threat actors to research potential attacks at speed, and craft convincing copy that compels users to act with urgency, all while being replicated on a previously unachievable scale. 

Fighting Back 

Andrew Harding, VP of Security Strategy at Menlo Security, points out that one of the most interesting things they observed was that “the majority of GenAI fraud was not for the purpose of credential theft. Instead, these impersonation sites attempted to trick people into entering highly personal information.” 

Going into more detail about the observed attacks, he explained that “these fake GenAI platforms promise to generate a résumé or similarly personal document. In addition to cybercriminals stealing sensitive and personal information, the returned document is typically a PDF, where malware can hide out and be delivered. In the past year, Menlo Security successfully thwarted hundreds of incidents of such GenAI fraud.” 

Defending From the Front 

The insidious nature of the threats to browsers, through a combination of leveraging user trust and deploying Gen AI to create ultra-realistic fraudulent images and text, necessitates a proactive approach to defense. Whilst advanced browser isolation, real-time threat intelligence, and machine learning-based detection systems will become ever-more essential to combat bad actors effectively, they may not (right now) be as easily accessible to smaller organizations as they are to larger ones. However, the adoption of a zero-trust framework, along with an organization-wide implementation of MFA, are steps in the right direction that businesses of all sizes can take. 

Adam Parlett
Adam Parlett

Adam Parlett is a cybersecurity marketing professional who has been working as a project manager at Bora for over two years. A Sociology graduate from the University of York, Adam enjoys the challenge of finding new and interesting ways to engage audiences with complex Cybersecurity ideas and products.

  • Adam Parlett
    Apache Tomcat Under Siege 2: Well-Hidden Payload
  • Adam Parlett
    NIST Adds SandboxAQ’s HQC as Their Newest PQC Standard
  • Adam Parlett
    Policy Statement Sheds Light on Upcoming UK Cybersecurity Bill
  • Adam Parlett
    New Lazarus Group Scam Targets Crypto Jobseekers

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

New Phishing Kit Starkiller Defeats Multi-Factor Authentication

February 23, 20264 Mins Read

ReliaQuest Uncovers Social Media Phishing Campaign Built on Trusted Tools

January 22, 20266 Mins Read

What Happens after a Phishing Email Lands in Your Inbox?

January 5, 20266 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}