{"id":4588,"date":"2025-06-12T10:03:56","date_gmt":"2025-06-12T10:03:56","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/06\/12\/top-3-evasion-techniques-in-phishing-attacks-real-examples-inside\/"},"modified":"2025-06-12T10:03:56","modified_gmt":"2025-06-12T10:03:56","slug":"top-3-evasion-techniques-in-phishing-attacks-real-examples-inside","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/06\/12\/top-3-evasion-techniques-in-phishing-attacks-real-examples-inside\/","title":{"rendered":"Top 3 Evasion Techniques In Phishing Attacks: Real Examples Inside\u00a0"},"content":{"rendered":"<p>    Top 3 Evasion Techniques In Phishing Attacks: Real Examples Inside\u00a0<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>Phishing attacks aren\u2019t what they used to be. Hackers no longer rely on crude misspellings or sketchy email addresses. Instead, they use clever tricks to dodge detection tools and fool even cautious users.\u00a0\u00a0<\/p>\n<p>Let\u2019s break down three evasion techniques that are increasingly common in phishing campaigns with real examples pulled from recent <strong><a href=\"https:\/\/any.run\/?utm_source=csn&amp;utm_medium=article&amp;utm_campaign=top3_evasion_techniques&amp;utm_content=landing&amp;utm_term=110625\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">ANY.RUN sandbox<\/a> <\/strong>analyses.\u00a0<\/p>\n<h2 class=\"wp-block-heading\"><strong>1. Hiding Malicious Links In QR Codes\u00a0<\/strong><\/h2>\n<p>Instead of sending a direct phishing link, attackers now embed the link inside a QR code, typically disguised as something harmless, like a login prompt, payment notice, or delivery update. <\/p>\n<p>The email might look clean to scanners, but once the user scans the code with their phone, they\u2019re taken straight to a phishing site.\u00a0<\/p>\n<p>Here\u2019s why this tactic is so effective and dangerous:\u00a0<\/p>\n<ul class=\"wp-block-list\">\n<li>\n<strong>Email filters don\u2019t \u201csee\u201d the link<\/strong> \u2013 QR codes are images, and many scanners don\u2019t decode or analyze their content. So even if the embedded link leads to a phishing page, it passes undetected.\u00a0<\/li>\n<\/ul>\n<ul class=\"wp-block-list\">\n<li>\n<strong>Mobile users are more vulnerable<\/strong> \u2013 Scanning a QR code on your phone doesn\u2019t show the full URL like hovering over a link on a desktop might. Most users just tap and proceed.\u00a0<\/li>\n<\/ul>\n<ul class=\"wp-block-list\">\n<li>\n<strong>The phishing site can look highly convincing<\/strong> \u2013 Victims may be tricked into entering credentials, credit card numbers, or 2FA codes, handing attackers access to business email accounts, payment systems, internal networks, personal and corporate data.\u00a0<\/li>\n<\/ul>\n<p>Luckily, there are solutions like ANY.RUN sandbox that can handle exactly this kind of evasive trick. <\/p>\n<p>When you upload a phishing email or file containing a QR code, the sandbox automatically detects the image, decodes it, and pulls out the link.\u00a0<\/p>\n<p><strong><a href=\"https:\/\/app.any.run\/tasks\/aed3ca77-194f-4749-8014-656c4dccbf27?utm_source=csn&amp;utm_medium=article&amp;utm_campaign=top3_evasion_techniques&amp;utm_content=task&amp;utm_term=110625\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">View analysis session with QR code<\/a>\u00a0<\/strong><\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjcH2pDG-19RURkpvwGNnQu0CkZmfLNOWz4g6yWFOQqfHosyemkUBKNnDZiBGHeVNIlkRtIyD3qrH1uiE1PwPO-ARCbBPWJVt-dgvT_I1nw1K988WfMrjIg33v4a2mLNvydxWum1f4xiJjLaCXB2SN-cDAw61Rt4jl15_ROr5In_MdHiwqj7KeyfAt6XyZ2\/s1926\/Screenshot%25202025-06-10%2520at%252013.22.58.webp?ssl=1\" alt=\"\"><figcaption class=\"wp-element-caption\">PDF document with QR code analyzed inside ANY.RUN sandbox\u00a0<\/figcaption><\/figure>\n<\/div>\n<p>Before starting the session here, we enabled the option \u201cautomated interactivity\u201d. This means the sandbox behaves like a real user. <\/p>\n<p>It scans the QR automatically, opens the embedded link in a browser and solved CAPTCHA without your manual intervention.\u00a0\u00a0<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgq8Usaoy-eMu3z-BhgNz8NXmfdTat5g-bkoTlDq1B-DLyDTwA6Qkik_AYcs-3_tVks0lK0jHaYLYIPs7_-sXQEGwmG7K42C0oR_yWqMgNzZ7Ph9hfvZS4PCQq8-GcabdKFPBwOChF3ZqXfpkFeCb72-GeMEPiBve6j6Df1jULuuQ2BuEF-GIx6ZF98OL3-\/s1325\/Screenshot%25202025-06-10%2520at%252013.33.38.webp?ssl=1\" alt=\"\"><figcaption class=\"wp-element-caption\">ANY.RUN sandbox opening the malicious link in the browser and solving CAPTCHA\u00a0<\/figcaption><\/figure>\n<\/div>\n<pre class=\"wp-block-code\"><code>See through phishing tricks in seconds. Access ANY.RUN with your 14-day trial and catch what other tools can\u2019t -&gt; <strong><a href=\"https:\/\/any.run\/demo?utm_source=csn&amp;utm_medium=article&amp;utm_campaign=top3_evasion_techniques&amp;utm_content=demo_1&amp;utm_term=110625\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Start your 14-day trial now<\/a>\u00a0<\/strong><\/code><\/pre>\n<p>As a result, the victim is redirected to a fake Microsoft login page for credentials theft.\u00a0<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEiB32LuM84eADIV0eyxJUFoImAjCjhIJ2RkKrTYHA4WKN9qP-MGpvEAOPTxtEghqWIB7EbnF7trh248K7Yx1dFrJbIP98jD81zfunWLguWMC5hNt7a-vFWZwiMkU0PkaqRaW0LhN3HAADiwoK6i__iFHbAJxC8mSmQIW0pkME5dnkzqp0a23OKWd-y32XuQ\/s1325\/Screenshot%25202025-06-10%2520at%252013.36.29.webp?ssl=1\" alt=\"\"><figcaption class=\"wp-element-caption\">Fake Microsoft login page for credentials theft discovered inside ANY.RUN\u00a0<\/figcaption><\/figure>\n<\/div>\n<p>Inside the sandbox, we can see how the <strong>entire attack chain is uncovered within seconds, <\/strong>from detecting the QR code to opening the phishing page and labeling the behavior. <\/p>\n<p>The verdict is clear: malicious activity is present.\u00a0<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgvMBY8on4NXuMgTgKp5jGsTsprepL3KlsZSmtuJ9zObX8tc5cGa4KhmqJHqbo2rSV__UGP4ewBipB4O8oT-aZMN4XUNUgGMkgoy4hcUMKAI_rH6oKJ5C3pWcl18aut3KnA91FdL7cZpyA8YU0XrNjA39pR1DxePBWFMndcJhh7isv3Spy1ptpZbGt7aIaU\/s772\/Screenshot%25202025-06-10%2520at%252013.43.21.webp?ssl=1\" alt=\"\"><figcaption class=\"wp-element-caption\">Malicious activity detected by interactive sandbox\u00a0<\/figcaption><\/figure>\n<\/div>\n<p>ANY.RUN automatically tags key elements of the attack with labels like <strong>\u201cQR code,\u201d \u201cphishing,\u201d<\/strong> and even campaign-specific indicators like <strong>\u201cTycoon\u201d<\/strong> when applicable. <\/p>\n<p>This gives analysts instant context without the need for manual digging.\u00a0<\/p>\n<p>By exposing the full threat flow in real time, <strong>detection time drops from hours to seconds<\/strong>, helping security teams:\u00a0<\/p>\n<ul class=\"wp-block-list\">\n<li>Quickly validate suspicious emails or files\u00a0<\/li>\n<li>Avoid chasing false positives\u00a0<\/li>\n<li>Take action before a user falls for the trap\u00a0<\/li>\n<\/ul>\n<p>In short, what would normally require deep manual analysis is now surfaced instantly with evidence, labels, and behavior insights all in one place.\u00a0<\/p>\n<h2 class=\"wp-block-heading\"><strong>2. Geotargeting And Redirect Chains\u00a0<\/strong><\/h2>\n<p>Some phishing campaigns don\u2019t show their hand right away. Instead of directly exposing malicious content, they carefully profile the victim first, based on <strong>location, browser settings, system details<\/strong>, and more. <\/p>\n<p>If the visitor fits the attacker\u2019s target criteria, they\u2019re quietly redirected to a phishing site. If not? They\u2019re sent somewhere else, such as a Tesla website.\u00a0\u00a0<\/p>\n<p>This technique, often used in campaigns like Tycoon2FA, helps attackers stay hidden and hyper-targeted.\u00a0<\/p>\n<p>In a <strong>recent Tycoon2FA phishing campaign<\/strong>, this conditional redirection was used to great effect.\u00a0\u00a0<\/p>\n<p><strong>Here\u2019s how it worked:\u00a0<\/strong><\/p>\n<p>The user visits a page (kempigd[.]com in this case) that quietly runs a fingerprinting script in the background. <\/p>\n<p>It collects details like screen resolution, WebGL renderer, plugins, and time zone to determine whether the visitor matches the attacker\u2019s target profile.\u00a0<\/p>\n<p>If the fingerprint doesn\u2019t match, the visitor is redirected to a legitimate site, in this case, Tesla\u2019s official website. This helps the phishing page appear harmless during casual or automated inspection.\u00a0<\/p>\n<p><strong><a href=\"https:\/\/app.any.run\/tasks\/57700913-657a-4c13-9719-2df531576970\/?utm_source=csn&amp;utm_medium=article&amp;utm_campaign=top3_evasion_techniques&amp;utm_content=task&amp;utm_term=110625\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">View Tesla website rediraction in ANY.RUN<\/a>\u00a0<\/strong><\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjTLWFvVEV5Q-JiA4SOD5femTZzXMuWsYkwTqghFkMMn2ql6cNw1Acni3YA-T9Qti3s3zdcfo6VMONcWCokT2kyhYYCp-whr6Gyoys5mKlr8-Ry09xLFgR7K9vcqoeOS55oC3XJAU8ID-Is_vUjaY_HL4OoqygRqVxZhePdRUAGbJnWrwvYwf4gDOoxJ1PX\/s1927\/Screenshot%25202025-06-10%2520at%252014.22.10.webp?ssl=1\" alt=\"\"><figcaption class=\"wp-element-caption\">Redirection to a legitimate Tesla website inside ANY.RUN sandbox\u00a0<\/figcaption><\/figure>\n<\/div>\n<p>If the fingerprint does match, the user is silently redirected to a phishing page designed to steal Microsoft 365 credentials.\u00a0<\/p>\n<p><strong><a href=\"https:\/\/app.any.run\/tasks\/7c54c46d-285f-491c-ab50-6de1b7d3b376?utm_source=csn&amp;utm_medium=article&amp;utm_campaign=top3_evasion_techniques&amp;utm_content=task&amp;utm_term=110625\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">View analysis with Microsoft phishing page<\/a>\u00a0<\/strong><\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgroO5QsKMb_XudXvl-uT3lpKGRoy3jZWQeGIgJzL0dZekupkqE6rB8yMaRuNconSegguBBsrkGZ62_-C7qblRbOq7TP-u70V29YB7wqkRKRu60kj0tsG3ihZUFULcge6_943nS2-vp_ouA3dBqlGEBYd688zECP-GOLEe-GElLMDFj0odz5S7OWzKc2hUw\/s1929\/Screenshot%25202025-06-10%2520at%252017.20.03.webp?ssl=1\" alt=\"\"><figcaption class=\"wp-element-caption\">Redirection to a fake Microsoft login page displayed inside ANY.RUN sandbox\u00a0<\/figcaption><\/figure>\n<\/div>\n<p>ANY.RUN\u2019s Interactive Sandbox lets analysts quickly change the VM\u2019s IP and other network settings to match the targeted geo to detonate the threat. <\/p>\n<p>This kind of fast analysis saves SOC teams hours of manual investigation by:\u00a0<\/p>\n<ul class=\"wp-block-list\">\n<li>Showing exactly how and why a redirect occurs\u00a0<\/li>\n<\/ul>\n<ul class=\"wp-block-list\">\n<li>Revealing phishing attempts that are invisible to standard scanning tools\u00a0<\/li>\n<\/ul>\n<ul class=\"wp-block-list\">\n<li>Confirming the threat with context-specific behavior tags\u00a0<\/li>\n<\/ul>\n<h2 class=\"wp-block-heading\"><strong>3. CAPTCHA Forms To Delay Detection\u00a0<\/strong><\/h2>\n<p>Phishing pages are becoming more interactive, and not just to mimic real sites. Some now use <strong>CAPTCHA challenges<\/strong> as a deliberate evasion step. <\/p>\n<p>These forms are designed to block bots, scanners, and automated security tools from reaching the actual malicious content.\u00a0<\/p>\n<p>By placing a CAPTCHA at the front of the attack chain, threat actors can delay detection or even prevent it entirely.\u00a0<\/p>\n<p><strong>Here\u2019s how this technique works:\u00a0<\/strong><\/p>\n<ol start=\"1\" class=\"wp-block-list\">\n<li>A phishing email or document leads to a seemingly clean link.\u00a0<\/li>\n<\/ol>\n<ol start=\"2\" class=\"wp-block-list\">\n<li>Upon opening, the user is presented with a CAPTCHA challenge.\u00a0<\/li>\n<\/ol>\n<ol start=\"3\" class=\"wp-block-list\">\n<li>Only after solving it does the real phishing page load, often mimicking services like Microsoft 365.\u00a0<\/li>\n<\/ol>\n<p><strong><a href=\"https:\/\/app.any.run\/tasks\/a6a71c6e-c2e3-4c61-9d7e-25b88b0872bd?utm_source=csn&amp;utm_medium=article&amp;utm_campaign=top3_evasion_techniques&amp;utm_content=task&amp;utm_term=110625\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">View the full sandbox session with CAPTCHA<\/a>\u00a0<\/strong><\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEh1HZ5kwuCS_wnMBHvFr35x_F9pGeHhNqtVLdGQ70h6XoNnyh6HMYQN2bo2y6JXbSSaSR41dIwqukZptVsjZmtyqXdFRWHqNz6IWkfKCuQu7_hfQLZFYGnMrWvqK3wsmob_o9jcFyzvdDZO1oC5rvTLSARUMlNyMX1opart2pOr5x3AwUox1tIbMQ3aaau3\/s1927\/Screenshot%25202025-06-10%2520at%252014.11.48.webp?ssl=1\" alt=\"\"><figcaption class=\"wp-element-caption\">CAPTCHA challenge used to delay access to the real phishing site\u00a0<\/figcaption><\/figure>\n<\/div>\n<p>To simulate the full flow, we enabled <strong>automated interactivity<\/strong> in ANY.RUN. This allowed the sandbox to solve the CAPTCHA just like a real user would, uncovering the next stage of the attack without any manual input.\u00a0<\/p>\n<p>As the form is completed, the victim is silently redirected to a <strong>fake Microsoft login page<\/strong>. <\/p>\n<p>Notably, the <strong>background image also changes<\/strong>, a tactic often used to reinforce the illusion of authenticity and distract from subtle design flaws.\u00a0<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjhaDQejs9voVcAuAovNV2ixYh3gySbEQIi5vRHZ8afWkQCb6dK8cBA2gconO43Oqa5o6EEeokTqeyRP6e_g3i1hbii1sL9SeJ6NAKDbQsELBi2ycBqW1oH5hQwjzxHYs9EDTWxRcigH-AXoT8DjZPsa95iPUJs7LOZ3EigeymlOg68HGo3eX7UhmDZU4Zs\/s2008\/Screenshot%25202025-06-10%2520at%252014.13.07.webp?ssl=1\" alt=\"\"><figcaption class=\"wp-element-caption\">Fake Microsoft 365 login page shown after CAPTCHA is bypassed\u00a0<\/figcaption><\/figure>\n<\/div>\n<p>This type of advanced analysis is important as automated tools usually stop at static analysis. They can\u2019t navigate CAPTCHAs, meaning they never see what comes next. But with ANY.RUN:\u00a0<\/p>\n<ul class=\"wp-block-list\">\n<li>The full post-CAPTCHA behavior is recorded\u00a0<\/li>\n<li>Malicious redirects and phishing logic are uncovered\u00a0<\/li>\n<li>Analysts don\u2019t waste time reproducing the flow manually\u00a0<\/li>\n<\/ul>\n<p>With one click, teams can validate evasive phishing attempts and move faster on response, without guessing what\u2019s hidden behind that CAPTCHA wall.\u00a0<\/p>\n<h2 class=\"wp-block-heading\"><strong>Final Thoughts: Evasive Tactics, Exposed In Seconds\u00a0<\/strong><\/h2>\n<p>As phishing attacks become more sophisticated, it\u2019s clear that traditional detection methods aren\u2019t enough. <\/p>\n<p>Techniques like QR code obfuscation, geotargeted redirects, and <a href=\"https:\/\/cybersecuritynews.com\/perimeterx-captcha-microsoft-account\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">CAPTCHA<\/a>-based delays are specifically designed to slip past static scanners and waste analysts\u2019 time.\u00a0<\/p>\n<p>But with solutions like ANY.RUN\u2019s interactive sandbox, you don\u2019t have to guess or waste hours reproducing complex attack flows.\u00a0<\/p>\n<ul class=\"wp-block-list\">\n<li>Watch evasive phishing tactics unfold in real time\u00a0<\/li>\n<li>Automatically extract indicators like malicious links, domains, or redirection chains\u00a0<\/li>\n<li>Detect and tag phishing behavior instantly, no matter how well it\u2019s hidden\u00a0<\/li>\n<li>Reduce investigation time from hours to seconds\u00a0<\/li>\n<li>Enable your team to respond faster, with full confidence in the verdict\u00a0<\/li>\n<\/ul>\n<p class=\"has-background\" style=\"background:linear-gradient(135deg,rgb(238,238,238) 100%,rgb(169,184,195) 100%)\"><a href=\"https:\/\/any.run\/demo?utm_source=csn&amp;utm_medium=article&amp;utm_campaign=top3_evasion_techniques&amp;utm_content=demo_2&amp;utm_term=110625\" target=\"_blank\" rel=\"noreferrer noopener nofollow\"><strong>Start your 14-day trial now<\/strong><\/a> and experience what real visibility into phishing looks like.\u00a0<\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/top-3-evasion-techniques-in-phishing-attacks-real-examples-inside\/\">Top 3 Evasion Techniques In Phishing Attacks: Real Examples Inside\u00a0<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Balaji N<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/top-3-evasion-techniques-in-phishing-attacks-real-examples-inside\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Top 3 Evasion Techniques In Phishing Attacks: Real Examples Inside\u00a0 Phishing attacks aren\u2019t what they used to be. Hackers no longer rely on crude misspellings or sketchy email addresses. Instead, they use clever tricks to dodge detection tools and fool even cautious users.\u00a0\u00a0 Let\u2019s break down three evasion techniques that are increasingly common in phishing [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1405,129,63,124,1406],"tags":[130],"class_list":["post-4588","post","type-post","status-publish","format-standard","hentry","category-any-run","category-cyber-security","category-cyber-security-news","category-phishing","category-phishing-attack","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/4588"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=4588"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/4588\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=4588"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=4588"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=4588"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}