Advanced phishing: techniques and defenses in 2025

New phishing and social engineering techniques in 2025: deepfakes, QRishing, MFA fatigue, and multi-channel attacks. How to defend yourself with an offensive approach.

Phishing is no longer the poorly written email full of grammatical errors.
In 2025, attackers are exploiting AI, deepfakes, and sophisticated psychological techniques to target employees and companies in increasingly convincing ways.

Most traditional controls such as spam filters, annual training, and MFA are no longer sufficient.
Cybercriminals know exactly how to overcome these barriers.

In this article, we analyze new advanced phishing techniques and the critical role of the offensive approach.

The attackers perfected three key elements:

1. Extreme customization

Thanks to public information (social media, conferences, LinkedIn) and datasets obtained from previous breaches, the messages are:

  • credible
  • contextualized
  • perfectly consistent with roles and responsibilities

The result? The filters detect nothing and the user remains unsuspecting.

2. Massive use of generative AI

Artificial intelligence is used for:

  • write flawless emails in any language
  • imitate corporate writing styles
  • generate voice deepfakes for spear-phishing calls
  • create infected documents that appear legitimate

3. Optimized psychological techniques

Attackers exploit cognitive biases—urgency, authority, familiarity—with great precision.
An "urgent" request from the CFO (via deepfake voice or cloned email) is a classic example.

Attackers bombard the user with authentication requests until they approve "by mistake."
Widespread in 2024–2025.

QRishing (QR code phishing)

A simple QR code leads to a perfectly credible clone page.
Many SOCs do not monitor this vector.

Deepfake Voice Phishing

Voice calls with a cloned voice of the CEO or IT manager.
Used to request:

  • urgent transfers
  • MFA codes
  • remote access

Browser-in-the-Browser Attack (BITB)

Login windowidenticalto the official one, but generated in the browser using CSS/JS. Steals MFA credentials and sessions.

Session hijacking using stolen tokens

The attacker does not steal the password, but thesession tokenspresent in the browser.
The victim does not notice anything.

Phishing on internal platforms

False messages about:

  • Teams
  • Slack
  • Notion
  • Google Drive


Users tend to trust internal tools more and verify less.

Many awareness programs are:

  • theorists
  • outdated
  • predictable
  • based on examples that are 5–10 years old

Users can recognize a fake email... butnot a malicious QR codeor avoice request from the CFO that is identical to the original.

A more realistic, practical, and dynamic approach is needed.

The offensive approach is not limited to "explaining phishing," butsimulates real techniquesand measures the company's reaction.

Activities include:

1. Advanced phishing simulations

  • voice deepfakes
  • multi-channel social engineering
  • cloud-based attacks
  • scenarios on Teams/Slack
  • user behavior analysis

2. Controlled exploitation of human vulnerabilities

Reproduction of real patterns used by attackers.

3. Evaluation of SOC detection

  • which attacks are detected
  • which go unnoticed
  • which logs are missing
  • which alerts are noisy or useless

4. Guided remediation

Not only training for users, but:

  • hardening of business flows
  • MFA improvement
  • session token protection
  • abnormal traffic monitoring

Users are not the weak link; they become so when systems leave them alone.

Modern phishing is not a matter of naivety: it is designed to deceive even experienced personnel.
Defense requires better tools, more robust processes, and, above all,realistic simulations.

With an offensive and controlled approach, companies can discover their weaknesses before attackers do.

Share this post: