HomeSecurityNew 'Point-and-Click' Phishing Kit Bypasses Security Filters

New 'Point-and-Click' Phishing Kit Bypasses Security Filters

A new phishing kit has appeared, which allows malicious users to create sophisticated lures with minimal technical expertise. This tool ‘point-and-click’ combines an intuitive web interface with powerful payload delivery mechanisms. Attackers can choose from pre-configured templates, customize branding elements, and target specific organizations or individuals.

See also: Hackers exploit Milesight routers to send phishing SMS

point-and-click phishing

Once a phishing page is deployed, victims are presented with seemingly harmless download prompts that actually trigger the delivery of malicious code. Early incidents show that the kit uses common file formats, such as Microsoft Office documents and HTML applications. Upon opening, the documents prompt users to enable macros or allow the execution of embedded scripts.

Assigning the heavy lifting to embedded script engines, the point-and-click kit builds payloads dynamically, making many static signature‑based defenses ineffective. Initial data shows a significant click‑through rate, indicating that the social engineering elements are highly persuasive. Analysts noted that the kit’s landing pages use dynamic content injection to bypass URL‑filtering solutions, rotating resource identifiers every few minutes. This approach thwarts automated scanners and contributes to prolonged dwell time on victim machines, enabling hidden staging and payload execution.

See also: MatrixPDF: New kit turns PDFs into phishing and malware baits

New 'Point-and-Click' Phishing Kit bypasses security filters

The researchers identified cases where payload download URLs were hidden behind multi-layered redirects, concealing their true destination until the final retrieval operation. Additionally, the researchers found that as soon as the victim triggers content execution, the embedded script runs a PowerShell command that retrieves and executes the final payload from a remote server. This PowerShell command is encoded in Base64 and wrapped in a compressed file, bypassing most heuristic detection engines. The victims remain unsuspected as the process runs with minimal user interaction and without visible windows.

At the heart of the kit's infection chain is an HTML Application (HTA) that acts as the initial loader. When the victim clicks 'Enable Editing' or 'Allow Blocked Content', the HTA file is executed. This snippet is decoded into a PowerShell that downloads an encrypted binary file, decrypts it in memory, and executes it directly from RAM. By operating in memory, the kit avoids writing malicious files to disk, undermining file-based detection.

The downloaded binary functions as a modular loader, retrieving additional components such as credential stealers or ransomware droppers. Persistence is achieved by creating a hidden scheduled task that restarts the loader every hour under the context of the logged-in user. This tactic ensures continuous access even if the original document is closed or the machine is rebooted. The name of the scheduled task is random for each campaign, complicating manual detection efforts.

See also: New Spear-Phishing Attack Distributes DarkCloud Malware

New 'Point-and-Click' Phishing Kit bypasses security filters

Overall, this phishing ‘point-and-click’ kit represents a significant escalation in accessible attack capabilities, combining user-friendly interfaces with advanced evasion and payload delivery techniques.

Selecting the team

🔑 Secure your passwords with Proton Pass

Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.

  • ✔ Encrypted storage of passwords & passkeys
  • ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
  • ✔ Free version — on all devices
Get your free Proton Pass →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS