Phishing Kits in 2026: ClickFix, QR Codes, MFA Bypass
Modern phishing kits bypass MFA, hide from scanners, and ask victims to run commands. See what the tools now do and which habits still work.
Modern phishing kits bypass MFA, hide from scanners, and ask victims to run commands. See what the tools now do and which habits still work.
Attackers no longer build phishing tools themselves. Instead, they rent kits. Those kits ship with working login pages, real-time MFA bypass, and filters that hide the page from security scanners. Two techniques now dominate: fake error prompts that ask the user to run a command, and QR codes that move the attack to a personal phone. Both target the person, not the software.
Table of Contents
ToggleA decade ago, running a convincing campaign took skill. Today it takes a subscription. Kits arrive with brand templates, hosting, and a dashboard that shows who opened the message and who typed in details.
That shift matters for defense. The attacker who sends you a flawless copy of your login page may have no technical skill at all. Phishing as a service describes that business model, and a phishing kit is what the subscription actually delivers.
The feature list reads like normal software, because that is what it is.
| Capability | What it does |
|---|---|
| Reverse proxy | Passes your login to the real site as you type |
| Real-time MFA bypass | Steals the session after you approve the prompt |
| Brand auto-matching | Loads the right logo for each victim |
| Scanner detection | Hides the page from security crawlers |
| Instant exfiltration | Sends stolen details straight to the attacker |
| Victim tracking | Reports who opened and who submitted |
Two of these deserve a closer look. A reverse proxy sits between the user and the real service. So the login works, the MFA prompt is real, and the attacker still walks away with the session. Scanner detection matters just as much, since a page that refuses to load for a security crawler never gets flagged at all.
Discover how Threatcop protects your workforce from modern cyber threats.
The fastest-growing method asks the victim to do the work themselves, which is a sharp break from how phishing emails used to look.
A page shows what looks like a failed check, often copying a familiar CAPTCHA screen. It then tells the user to press a key combination and paste a command to fix it. The user runs the command, and it installs whatever the attacker chose.
The growth is startling. Proofpoint recorded a roughly 400% rise in links tied to this technique between May 2024 and May 2025. ESET measured a 517% surge in the first half of 2025, which made it the second most common attack type it blocked. Microsoft’s own 2025 reporting put it ahead of normal phishing as a way in.
Nobody sends an attachment, so most training misses this entirely. No bad file crosses the gateway. The victim pastes the command, which is why patched machines with endpoint tools still fall for it.
QR codes solve a different problem for attackers. An image holds no clickable link for a filter to read. Scanning it also moves the victim to a personal phone, outside company controls.
Proofpoint identified over 4.2 million QR code phishing threats in the first half of 2025 alone. QR code phishing also defeats normal link checks, because there is no text URL to compare against a blocklist.
The lesson is that the device matters. A work laptop may block the destination, while the employee’s own phone has no such guard.
Each technique above removes a signal that older training taught people to watch for.
Replace those checks with habits that still hold. First, open login pages from a bookmark, not a message. Next, let a password manager fill the form, since it will not autofill on a lookalike domain. Then never paste a command you did not write. Finally, treat an unexpected MFA prompt as a sign that someone already has your password.
Generic phishing training does not carry over to these methods. Someone who can spot a bad attachment has learned nothing about a fake check screen that asks them to paste a command.
Threatcop Security Awareness Training (TSAT) runs simulations across the vectors attackers actually use, including QR code lures and attachment-based phishing alongside email, SMS, and voice. That range matters, because a program that tests only email covers a shrinking share of the real risk.
Its Employee Vulnerability Score splits the people who only clicked from those who typed in details or ran something. That split decides whether an incident happened. Average breach time shows how long from lure to compromise. Repeat-offender flagging then points coaching at the staff who keep falling for the same format. AI-based template generation keeps lures current, so the test matches this quarter’s technique rather than last year’s.
The tools have grown up while much training has not. So update what you teach. Drop the advice about spelling and padlocks, because kits defeat both. Teach three habits instead: open login pages from bookmarks, never paste a command you did not write, and treat an unexpected MFA prompt as evidence your password is already gone. Then test those habits with simulations that include QR codes and fake verification screens, not just email attachments. The techniques will keep changing, so the measure that matters is not whether people recognize this quarter’s lure. It is how quickly they report something that feels wrong, which makes fast reporting the one measure worth tracking.
Most buy or rent phishing kits. These supply brand templates, hosting, login pages, and dashboards. Many add reverse-proxy features that defeat MFA in real time, plus filters that hide the page from security scanners.
ClickFix shows a fake error or check screen, then tells the user to paste and run a command to fix it. The victim runs the code themselves. So no attachment crosses the email gateway, and endpoint tools often see nothing odd.
Yes, through a reverse proxy. The fake page passes your login to the real service, which sends you a real MFA prompt. Once you approve it, the attacker takes the session and no longer needs your code.
A QR code holds no readable link, so email filters have little to check. Scanning it also moves the victim to a personal phone, which usually sits outside company controls.
Security awareness training works when it covers the exact technique. Advice about spelling errors and attachments does not carry over to a fake check screen or a QR code. So simulations need to include those formats directly.
Anjali is the Cybersecurity Manager at Kratikal, leading a team focused on strengthening security through rigorous vulnerability assessments and penetration testing. With expertise across web, network, and cloud environments, she drives strategies to safeguard clients’ critical assets while mentoring her team and staying ahead of escalating cyber threats.
Anjali is the Cybersecurity Manager at Kratikal, leading a team focused on strengthening security through rigorous vulnerability assessments and penetration testing. With expertise across web, network, and cloud environments, she drives strategies to safeguard clients’ critical assets while mentoring her team and staying ahead of escalating cyber threats.
Attackers research your staff before writing a single email. See what OSINT reveals, where it comes from, and how...
Federal support for state and local cyber defense ended in 2025 while attacks rose. See what changed, and the...
Gateways filter mail before delivery. API-based tools inspect it inside the mailbox. See how they differ, where each fails,...
Table of Contents
×