Malicious URLs overtake email attachments as the biggest malware threat
With malware threats surging, research from Proofpoint highlights the increasing use of off-the-shelf 'phish kits' like CoGUI and Darcula
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
You are now subscribed
Your newsletter sign-up was successful
There's been a sharp rise in the number of phishing and URL-based attacks over the last year, with malicious URLs now being used four-times as often as attachments in email threats.
Malicious links are embedded in messages, buttons, and even within attachments like PDFs or Word documents to entice clicks that initiate credential phishing or malware downloads.
According to a new report from Proofpoint, researchers observed around 3.7 billion URL-based threats over a six month period, highlighting the growing scale of the problem.
Only 8.3 million of these threats were intended to deliver malware, however, with the most frequently-observed payloads in URL-based campaigns being remote monitoring and management (RMM) tools and remote access software (RAS).
These attacks are getting increasingly difficult for users to identify, Proofpoint noted, with cyber criminals now using advanced social engineering techniques and AI-generated content to create their malicious URLs.
Not only are they impersonating trusted brands, but also abusing legitimate services, tricking users with fake error prompts and bypassing traditional security by embedding threats in QR codes and SMS messages.
"URL-based phishing threats are no longer confined to the inbox, they can be carried out anywhere and are often extremely difficult for people to identify,” said Selena Larson, senior threat intelligence analyst at Proofpoint.
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
New techniques are paying off for hackers
Some of the URL-based credential phishing campaigns with the highest volumes in the past 12 months have been facilitated by off-the-shelf 'phish kits' like CoGUI and Darcula.
CoGUI is primarily used by Chinese-speaking threat actors, according to Proofpoint. These high-volume campaigns typically include message counts ranging from the hundreds of thousands to tens of millions at a time, and are mainly used to steal personal details such as credit card numbers.
Meanwhile, ClickFix malware campaigns - a phishing technique that lures users into running malicious code by displaying fake error messages or CAPTCHA screens - are up by nearly 400% year-over-year.
Malware operators are exploiting the urge to resolve a perceived technical issue, helping them spread remote access trojans (RATs), infostealers and loaders.
QR code and smishing threats are rising
Proofpoint also identified more than 4.2 million QR code phishing threats in the first half of 2025 alone. In these cases, the main aim of attackers is credential phishing, with 3.7 billion URL-based attacks aimed at stealing logins.
With phishing lures that impersonate trusted brands and use off-the-shelf tools such as CoGUI and Darcula phish kits, Proofpoint said even low-skilled actors can deploy highly convincing campaigns that bypass multi-factor authentication (MFA) and lead to full account takeover.
The number of smishing campaigns rocketed by 2,534%, as attackers shift their focus to mobile devices - at least 55% of suspected SMS-based phishing messages analyzed by the firm contained malicious URLs, often mimicking government communications or delivery services.
“From QR codes in emails and fake CAPTCHA pages to mobile-first smishing scams, attackers are weaponizing trusted platforms and familiar experiences to exploit human psychology," said Larson.
"Defending against these threats requires multi-layered, AI-powered detection and a human-centric security strategy.”
Make sure to follow ITPro on Google News to keep tabs on all our latest news, analysis, and reviews.
MORE FROM ITPRO
Emma Woollacott is a freelance journalist writing for publications including the BBC, Private Eye, Forbes, Raconteur and specialist technology titles.
-
Researchers call on password managers to beef up defensesNews Analysts at ETH Zurich called for cryptographic standard improvements after a host of password managers were found lacking
-
Is there a future for XR devices in business?In-depth From training to operations, lighter hardware and AI promise real ROI for XR – but only if businesses learn from past failures
-
Researchers called on LastPass, Dashlane, and Bitwarden to up defenses after severe flaws put 60 million users at risk – here’s how each company respondedNews Analysts at ETH Zurich called for cryptographic standard improvements after a host of password managers were found lacking
-
‘They are able to move fast now’: AI is expanding attack surfaces – and hackers are looking to reap the same rewards as enterprises with the technologyNews Potent new malware strains, faster attack times, and the rise of shadow AI are causing havoc
-
Ransomware gangs are using employee monitoring software as a springboard for cyber attacksNews Two attempted attacks aimed to exploit Net Monitor for Employees Professional and SimpleHelp
-
Security experts warn Substack users to brace for phishing attacks after breachNews Substack CEO Christ Best confirmed the incident occurred in October 2025
-
Google issues warning over ShinyHunters-branded vishing campaignsNews Related groups are stealing data through voice phishing and fake credential harvesting websites
-
Notepad++ hackers remained undetected and pushed malicious updates for six months – here’s who’s responsible, how they did it, and how to check if you’ve been affectedNews Hackers remained undetected for months and distributed malicious updates to Notepad++ users after breaching the text editor software – here's how to check if you've been affected.
-
CISA’s interim chief uploaded sensitive documents to a public version of ChatGPT – security experts explain why you should never do thatNews The incident at CISA raises yet more concerns about the rise of ‘shadow AI’ and data protection risks
-
Former Google engineer convicted of economic espionage after stealing thousands of secret AI, supercomputing documentsNews Linwei Ding told Chinese investors he could build a world-class supercomputer
