Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Phishing - KnowBe4 Report Finds Polymorphic Phishing Features Present in 76.4% of Campaigns
Phishing Attacks Latest News News & Analysis Study & Research

KnowBe4 Report Finds Polymorphic Phishing Features Present in 76.4% of Campaigns

Adam ParlettBy Adam ParlettMarch 31, 20254 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Phishing
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

Phishing attacks are on the rise, with the latest KnowBe4 Phishing Threat Trends Report observing a 17.3% increase in phishing emails between September 15th, 2024, and February 14th, 2025, compared to the previous six months. Also increasing is the use of Polymorphic phishing, with polymorphic phishing features identified in 76.4% of all phishing campaigns they observed. 

Not only are attacks increasing, but they are also getting more sophisticated; the report saw a 22.6 percent increase in ransomware payloads, with phishing hyperlinks, malware, and social engineering payloads all bypassing traditional detection methods a lot more frequently. This was identified as an accelerating trend, as within that sixth-month period, they observed a 57.5% increase over the previous three months from November 1st, 2024, to February 15th, 2025. 

Changing the Bait: Polymorphic Phishing 

Polymorphic phishing attacks involve a series of emails that aren’t uniform because they contain subtle changes. They begin by attempting to obtain user credentials and then utilize those credentials to target others. The report identified a 57.9% increase in attacks being sent from compromised accounts. This method makes it challenging for secure email gateways (SEGs) and other traditional defensive tools to identify and block these messages. The lack of uniformity complicates rule updates for security teams, as historically, strategies have been focused on identifying commonalities like payloads or sending domains. 

The three most common changes to circumnavigate security were found to be replacing logos, changing the destination of a link, and altering the sender. Another popular method involves adding randomized characters and symbols to email subject lines. Doing so helps to disguise malicious emails behind the email preview cutoff and can avoid them being blocked by hash mapping, as organizations are reluctant to narrow their parameters too much so as not to damage operational efficiency. 

Obfuscation Through Heavier Payloads 

In their six-month report observation, KnowBe4 found that three payload types had experienced substantial increases in their ability to bypass Microsoft and SEG detection compared to the previous six months. These were a 36.8% increase in phishing hyperlinks, a 20% increase in malware, and a 14.2% increase in social engineering. Cybercriminals are benefitting from an emerging shadow economy that includes the ability to purchase phishing kits from crime-as-a-service (CaaS) platforms where vendors offer phishing “kits” for a subscription fee. 

The report highlights HTML smuggling as the most popular current obfuscation technique for masking malicious payloads from file-scanning AV technologies. It points out that file sizes for both malware attachments (including ransomware) and malicious HTMLs have also increased year on year, and attribute this to “cybercriminals attempt to improve deliverability by maxing out email latency service-level agreements (SLAs) before an attack is detected.” 

Breaking Down an Advanced Ransomware Payload 

KnowBe4 deconstructed a complex INC Ransomware payload attached to a phishing email they had discovered in their research to illustrate some of the threats they were encountering. These included: 

  • JavaScript payload obfuscation: multiple layers that included a password-protected zip file and HTML smuggling to bypass signature-based detection. 
  • AI-generated obfuscation: randomly generated text to confuse security scanners. 
  • Malicious URL obfuscation: script reverse and Base64 encoding to avoid featuring on blocked lists. 

Advocating for AI and Zero-Trust 

Jack Chapman, SVP of Threat Intelligence at Know Be4, advocates for AI-powered detection underpinned by a zero-trust approach when it comes to modern security solutions. While stating that signature-based and reputation-based detection provide a solid foundation, he adds that “on its own, it’s no longer enough to hold back the tide of phishing attacks targeting organizations. Success in phishing equals a payday for cybercriminals — and these email security platforms are the first hurdle for cybercriminals to jump.” 

Adam Parlett
Adam Parlett

Adam Parlett is a cybersecurity marketing professional who has been working as a project manager at Bora for over two years. A Sociology graduate from the University of York, Adam enjoys the challenge of finding new and interesting ways to engage audiences with complex Cybersecurity ideas and products.

  • Adam Parlett
    Apache Tomcat Under Siege 2: Well-Hidden Payload
  • Adam Parlett
    NIST Adds SandboxAQ’s HQC as Their Newest PQC Standard
  • Adam Parlett
    Policy Statement Sheds Light on Upcoming UK Cybersecurity Bill
  • Adam Parlett
    New Lazarus Group Scam Targets Crypto Jobseekers

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

New Phishing Kit Starkiller Defeats Multi-Factor Authentication

February 23, 20264 Mins Read

ReliaQuest Uncovers Social Media Phishing Campaign Built on Trusted Tools

January 22, 20266 Mins Read

What Happens after a Phishing Email Lands in Your Inbox?

January 5, 20266 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}