Get a free trial →

Push Logo

Phishing attacks: how to detect and stop modern phishing

Geometry graphic

Phishing attacks are outpacing the tools built to stop them

How modern phishing attacks work

  1. The attacker creates a phishing page using a kit or AI-generated template
  2. Infrastructure is spun up on trusted or newly registered domains
  3. The lure is delivered through email, messaging apps, search ads, or social platforms
  4. The page is only active when triggered, often disappearing after use
  5. The attacker rotates infrastructure and repeats the process

Why traditional phishing defenses fall short

Diagram showing how zero-day phishing evades email filters and URL reputation tools by using newly registered domains, dynamic pages, and bot detection.

How do you detect and stop modern phishing?

Push Security real-time browser alert detecting zero-day phishing behavior and blocking credential theft before the user submits their login details.

How Push detects and stops phishing, regardless of technique, payload, or delivery channel

Push Security real-time browser alert detecting zero-day phishing behavior and blocking credential theft before the user submits their login details.

Frequently asked questions

A pre-packaged toolkit that enables attackers to deploy phishing infrastructure quickly — typically including cloned login page templates, credential capture mechanisms, hosting automation, and anti-detection features. Modern phishing kits operate as Phishing-as-a-Service (PhaaS) platforms with subscription access, customer support, and automated infrastructure rotation.

AiTM kits (such as Tycoon 2FA, Evilginx, Sneaky 2FA) include reverse proxy functionality that captures post-MFA session tokens. ClickFix kits include clipboard hijacking and fake CAPTCHA templates.

Push detects phishing kits at the technique-class level — targeting behavioral signatures (reverse proxy behavior, credential harvesting, clipboard manipulation) — meaning detections remain effective across many kits and configurations.

Phishing attacks using newly created infrastructure — domains, pages, and kits — that haven't been identified or blocklisted by any security vendor. The phishing page is "zero-day" in the sense that no threat intelligence exists for it when the user encounters it.

This isn't a niche problem — 89% of phishing domains are active for fewer than two days. Attackers spin up infrastructure, use it for a campaign, and discard it before blocklists react. Any defense relying on "known-bad" indicators has a structural detection lag. Push detects phishing behaviorally — analyzing page structure and phishing kit mechanics at the rendered-page level.

Phishing succeeds because the defenses most organizations have deployed rely on known indicators — domains, URLs, and file hashes — and modern phishing operations rotate those indicators faster than any blocklist or reputation service can track. The tools aren't failing at what they do; the attack has moved beyond what they were designed to catch.

Infrastructure rotation means phishing domains are discarded and replaced before blocklists react. Trusted domain abuse means attackers host phishing pages on microsoft.com, google.com, chatgpt.com, and other domains that no reputation filter would block. Bot protection means the phishing page only appears to real users — 95% of in-browser attacks detected by Push used anti-analysis services that serve benign content to automated scanners. And multi-channel delivery means phishing arrives through search ads, QR codes, SMS, messaging apps, and social platforms as well as email — but email security only covers one of those channels. The root cause is that most phishing defenses analyze indicators rather than behavior.

Blocklist-based detection requires someone to report a site before it can be blocked — which means every new phishing page gets at least one victim before defenses react. Behavioral phishing detection eliminates that gap by analyzing page behavior in real time, identifying phishing kit mechanics regardless of whether the domain has been seen before.

Push detects unreported phishing sites because phishing kits have behavioral signatures that persist across campaigns, domains, and infrastructure rotation. Even on a brand-new domain with no threat intelligence, the kit's mechanics are recognizable.

No. SWGs rely on URL categorization and domain reputation — indicators that don't exist for zero-day infrastructure. Some SWGs offer real-time URL analysis, but phishing kits with bot protection serve benign content to automated scanners.

Push operates inside the browser as the user sees it, detecting phishing kit behavior at the rendered-page level. The two are complementary: SWGs for known-bad blocking, Push for zero-day behavioral detection. Read about SWG limitations.

Email security can catch some through time-of-click URL analysis and sandboxing, but effectiveness is limited. Phishing kits with bot protection defeat automated scanners. URL reputation checks miss newly created domains. And a growing share of phishing arrives outside email entirely.

Push detects the phishing page itself, regardless of whether the link was already known-bad and regardless of delivery method.

Identifying phishing by analyzing what a page does — its DOM structure, script behavior, credential-harvesting mechanics, and user interaction patterns — rather than matching against known indicators. It detects the technique, not the specific instance.

Push targets technique-class signatures: AiTM reverse proxy behavior, cloned login page construction, Browser-in-the-Browser pop-ups, ClickFix clipboard manipulation, and credential-harvesting patterns. These remain consistent even as attackers rotate infrastructure. Read about the Pyramid of Pain and behavioral detection.

Infrastructure rotation: phishing domains are active fewer than two days, outpacing blocklists. Trusted domain abuse: hosting phishing on microsoft.com, google.com, or chatgpt.com. Bot protection: serving benign content to automated scanners. Non-email delivery: a significant share of phishing arrives via channels email filters never see.

The underlying problem is structural — email filters analyze links, but the phishing attack lives in the rendered page. Push operates at the destination, detecting phishing behavior inside the browser. Read about phishing evasion techniques.

89% of phishing domains are active for fewer than two days, with just 6.5% surviving more than 15 days. PhaaS platforms automate this rotation — generating fresh infrastructure for each campaign and discarding it before blocklists react.

This speed makes any indicator-based defense structurally too slow. Push detects phishing behaviorally at the page level, so domain rotation is irrelevant. Read about the Pyramid of Pain.

Focus on page behavior, not content quality. AI-generated phishing pages can look visually identical to the real login page while having no resemblance to its underlying code — the attacker describes what they want and the AI builds it from scratch. This defeats detection that relies on visual tells (grammar errors, awkward branding) and makes template-matching against known page structures less reliable. But AI doesn't change the underlying phishing mechanics. The page still needs to harvest credentials, proxy authentication, or execute malicious code.

Push's behavioral detection targets those mechanics. An AI-generated AiTM proxy still exhibits reverse proxy behavior. An AI-generated ClickFix page still manipulates the clipboard. Content quality is irrelevant to the detection model. Read about AI and phishing.

AiTM kits like Tycoon 2FA and Evilginx proxy the real login page from a cloned frontend, either by literally cloning the real page (with some changes to evade fingerprinting controls looking for this) or asking an AI tool to recreate a page from a screenshot. The latter approach usually results in a convincing appearance without any overlap in the codebase or structure of the page, and is a highly effective way of evading detection controls based on cloned page signatures.

Push detects both — AiTM reverse proxy behavior and cloned login page signatures — regardless of the domain hosting them. Read about phishing kit techniques.

The approaches most organizations rely on don't hold up well here. URL blocklists and Safe Browsing miss phishing on newly registered domains — most are active for less than two days. Domain monitoring and brand protection only catch typosquatting, not phishing hosted on unrelated or legitimate domains. Email link scanning only covers email-delivered phishing, missing search ads, QR codes, social media, and direct navigation. IdP-side defenses like Okta ThreatInsight use IP reputation, which residential proxies defeat.

Behavioral detection in the browser is the approach that works regardless of IdP. Push identifies AiTM reverse proxy behavior, cloned login page signatures, and credential harvesting patterns at the rendered-page level — the phishing technique is the same whether the kit impersonates Microsoft, Okta, or Google. Read about behavioral phishing detection.

For Microsoft 365: Tycoon 2FA, Sneaky 2FA, FlowerStorm, Evilginx, EvilProxy, and NakedPages. For Google Workspace: Evilginx, EvilProxy, and NakedPages. For Okta: Evilginx and real-time operated panels like Doko's Panel. Most kits — such as Evilginx, EvilProxy, and Doko's Panel — support multiple targets.

Push detects phishing kits at the technique-class level — targeting reverse proxy behavior, credential harvesting, and cloned login page signatures.