Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

AI-Driven Phishing and QR Code Quishing Surge in 2025 Spam and Phishing Report

The 2025 landscape for spam and phishing has seen an increase in AI-generated lures and QR code-based "quishing," alongside complex malware campaigns that exploit cracked games and software to deploy information stealers on a large scale.

The 2025 landscape for spam and phishing has seen an increase in AI-generated lures and QR code-based "quishing," alongside complex malware campaigns that exploit cracked games and software to deploy information stealers on a large scale.

These developments underscore how social engineering techniques and multi-stage loaders are increasingly used to bypass traditional security measures and monetize stolen data.

Threat actors are employing generative AI to craft phishing emails, instant messages, and fake login pages that accurately mimic brand tone, grammar, and localized language. Large volumes of customized messages can be generated rapidly, allowing campaigns to tailor content dynamically based on user profiles, geolocation, or current events. This approach reduces the effectiveness of traditional red flags such as poor language and inconsistent branding.

AI is also utilized to create look-alike chatbot interfaces and fraudulent "support assistant" interactions that lead victims to enter credentials or payment information into attacker-controlled forms. Coupled with deepfake logos and cloned website designs, these tactics make phishing pages more difficult to distinguish from legitimate websites, even for experienced users.

In 2025, QR-based phishing, or "quishing," became more prevalent as attackers moved from using obvious malicious links to embedding scannable codes in emails, PDF invoices, office signage, and printed notices. Security tools that emphasize URL reputation and link scanning often overlook QR images, while users typically scan them with personal mobile devices that may not be as closely monitored as corporate endpoints.

This approach reduces the effectiveness of traditional red flags such as poor language and inconsistent branding.
Leo Underwood · Thehackingpost

Once scanned, these codes redirect victims to credential-harvesting portals, MFA token theft pages, or malware-hosting sites disguised as legitimate services. In some cases, attackers follow up with AI-written messages prompting victims to take further actions, enhancing the effectiveness of the initial QR lure.

Malware Campaigns via Pirated Software

Parallel to phishing trends, 2025-2026 witnessed large-scale campaigns exploiting pirated games and cracked software to distribute the RenEngine loader, which deploys HijackLoader and infostealers such as Lumma and ACR Stealer. These operations use modified game launchers to run a hidden malware chain while displaying a fake loading screen. Kaspersky identifies RenEngine as Trojan.Python.Agent.nb and HEUR:Trojan.Python.Agent.gen, with activity traced back to March 2025.

RenEngine drops multiple components into temporary directories and abuses legitimate executables and DLLs for side-loading, ultimately handing control to HijackLoader. HijackLoader employs techniques such as DLL side-loading, module stomping, process hollowing, and process doppelgänging to inject the final payload into trusted processes. This campaign has compromised hundreds of thousands of systems globally, stealing browser credentials, cookies, crypto wallets, and system data.

To counter AI-driven phishing and quishing, organizations should combine secure email gateways with computer vision and content analysis capable of detecting QR codes, brand impersonation, and dynamically generated phishing templates. User training should emphasize the risks associated with QR codes, AI-polished messages, and MFA token theft, providing guidance to verify codes and links through official channels before entering credentials.

Advertisement

Endpoint protection and behavior-based detection are crucial against loader chains like RenEngine and HijackLoader, especially on systems used for gaming or running unvetted software. Blocking pirated software, enforcing application control, and monitoring for anomalous activities can significantly reduce the impact of these campaigns.

Overall, the data from 2025 indicates a convergence of social engineering and stealthy loaders, making it necessary for defenders to enhance both user awareness and technical detection capabilities.

Based on reporting by GBHackers.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories