CyberHappenings logo

Track cybersecurity events as they unfold. Sourced timelines. Filter, sort, and browse. Fast, privacy‑respecting. No invasive ads, no tracking.

GhostFrame Phishing Framework Exploits Iframe Architecture for Over One Million Attacks

First reported
Last updated
1 unique sources, 1 articles

Summary

Hide ▲

A new phishing framework named GhostFrame has been linked to over one million attacks. Built around a stealthy iframe architecture, GhostFrame conceals malicious behavior within embedded iframes, allowing attackers to evade detection and dynamically adjust phishing content. The framework employs anti-analysis controls and randomized subdomains to maintain stealth and ensure attack continuity. GhostFrame's attack chain involves a benign-looking outer page that loads a secondary phishing page within an iframe, which contains the actual credential-harvesting components. The framework's emails vary widely in themes, including fake contract notices, HR updates, and password reset requests.

Timeline

  1. 04.12.2025 16:30 1 articles · 23h ago

    GhostFrame Phishing Framework Linked to Over One Million Attacks

    GhostFrame, a new phishing framework built around a stealthy iframe architecture, has been linked to over one million attacks. The framework conceals malicious behavior within embedded iframes, allowing attackers to evade detection and dynamically adjust phishing content. The attack chain involves a benign-looking outer page that loads a secondary phishing page within an iframe, which contains the actual credential-harvesting components. The framework employs anti-analysis controls and randomized subdomains to maintain stealth and ensure attack continuity.

    Show sources

Information Snippets