August 2025 Trends Report on Phishing Emails

Sept. 16, 2025, 2:10 p.m.

Description

The analysis reveals that phishing was the predominant threat in email attachments during August 2025, accounting for 63% of cases. Threat actors employed HTML scripts to replicate legitimate login pages and promotional content, aiming to capture user credentials. The report highlights an increase in malware distribution through document files exploiting vulnerabilities, such as the Equation Editor EQNEDT32.EXE vulnerability (CVE-2017-11882), leading to Purecrypter malware execution. Additionally, there's a rising trend in distributing PE files compressed in ZIP formats via phishing emails. The analysis covers Korean language phishing emails, providing insights into commonly used keywords and attachment types. The report also includes statistics on attachment file extensions and distribution trends over the past six months.

Date

  • Created: Sept. 16, 2025, 1:41 p.m.
  • Published: Sept. 16, 2025, 1:41 p.m.
  • Modified: Sept. 16, 2025, 2:10 p.m.

Indicators

  • e1e18483c6800d76f4818c05776c3bf523d682a0fc11e14b204e95d150476965
  • 54dd2aee467659e4108ef5824c8f28c614d520576b073e85f61e72d19df4c0fd
  • 50dd487e84be733b7f36936f3bfc372a7a405284d17db48e188d91b8a46efe55
  • 35a6c90aeed158cbca180d1b3116e6d07cdfdc41731243f01896bec972b99255

Attack Patterns

Linked vulnerabilities