Threat Spotlight: Speed, Scale, and Stealth: How Axios Powers Automated Phishing
Sept. 10, 2025, 8:11 a.m.
Description
Axios user agent activity has surged by 241% from June to August 2025, outpacing other flagged user agents. Attacks combining Axios with Direct Send achieved a 70% success rate in recent campaigns, significantly higher than non-Axios campaigns. The combination exploits Direct Send's trusted nature and Axios's lightweight design to bypass traditional security defenses. Attackers are using Axios to automate phishing, credential stealing, and API exploitation at unprecedented scale. The campaign initially targeted high-profile individuals in finance, healthcare, and manufacturing, but has expanded to include everyday users. Organizations are advised to implement robust detection mechanisms for suspicious user-agent activity, particularly Axios-related patterns, to mitigate this evolving threat.
Tags
Date
- Created: Sept. 10, 2025, 7:52 a.m.
- Published: Sept. 10, 2025, 7:52 a.m.
- Modified: Sept. 10, 2025, 8:11 a.m.
Indicators
- 185.168.208.63
- 185.168.208.62
- 185.168.208.61
- 185.168.208.60
- 185.168.208.44
- 185.168.208.59
- 185.168.208.36
- 185.168.208.55
- 178.130.47.216
- ogyhr.es
- ooox.hrcbods.es
- ywnlzl.dwqewi.es
- bsfff.es
- cpewyx.es
Additional Informations
- Healthcare
- Finance
- Manufacturing