{"id":2750,"date":"2025-09-10T04:53:59","date_gmt":"2025-09-10T04:53:59","guid":{"rendered":"https:\/\/ft365.org\/index.php\/2025\/09\/10\/axios-user-agent-helps-automate-phishing-on-unprecedented-scale\/"},"modified":"2025-09-10T04:53:59","modified_gmt":"2025-09-10T04:53:59","slug":"axios-user-agent-helps-automate-phishing-on-unprecedented-scale","status":"publish","type":"post","link":"http:\/\/ft365.org\/index.php\/2025\/09\/10\/axios-user-agent-helps-automate-phishing-on-unprecedented-scale\/","title":{"rendered":"Axios User Agent Helps Automate Phishing on \u201cUnprecedented Scale\u201d"},"content":{"rendered":"<div>\n<p><img decoding=\"async\" src=\"https:\/\/ft365.org\/wp-content\/uploads\/2025\/06\/localimages\/ea721ff9-8ba4-4d88-b386-57e9e1606077.jpg?width=64&#038;height=64&#038;mode=crop&#038;scale=both&#038;format=webp\" alt=\"Photo of Phil Muncaster\" loading=\"lazy\"><\/p>\n<\/div>\n<div id=\"cphContent_pnlArticleBody\" data-layout-id=\"2\" data-edit-folder-name=\"text\" data-index=\"0\">\n<p>Security experts have warned of a huge uptick in automated phishing activity abusing the Axios user agent and Microsoft\u2019s Direct Send feature.<\/p>\n<p>ReliaQuest claimed in a new report today that it observed a 241% increase in phishing activity using Axios between June and August 2025. Axios accounted for nearly a quarter (24%) of all malicious user-agent activity analyzed in the period, making it 10 times more common than any other agents tracked by ReliaQuest.<\/p>\n<p>The threat intelligence vendor said Axios-powered attacks had a 58% success rate versus just 9% for incidents without the user agent.<\/p>\n<p>What started as a campaign targeting executives and managers in sectors like finance, healthcare and manufacturing has now broadened to regular internet users, it added.<\/p>\n<p><em>Read more on phishing: Tycoon Phishing Kit Utilizes New Capabilities to Hide Malicious Links<\/em><\/p>\n<p>Axios is a lightweight, promise-based HTTP client that enables attackers to scale their phishing campaigns with little effort, the report claimed.<\/p>\n<p>Although a legitimate tool, the agent\u2019s ability to intercept, modify\u00a0and replay HTTP requests with ease and blend seamlessly into workflows makes it particularly prized.<\/p>\n<p>\u201cIts promise-based API and middleware interceptors let attackers log, tweak, replay, and troubleshoot easily. This makes it easier to bypass multifactor authentication (MFA), hijack session tokens, and tailor attacks to each target,\u201d said ReliaQuest.<\/p>\n<p>\u201cIn the Axios activity we saw, QR codes and phishing domains set the trap, then Axios let attackers exploit the data they captured. In the incidents we observed, Axios played a pivotal role in interacting with APIs and bypassing MFA protections.\u201d<\/p>\n<p>Other user agents require threat actors to write complex custom scripts or rely on tools that are more obviously suspicious, whereas Axios combines flexibility and easy automation, and will pass most user-agent analysis and reputation-based filter checks, the report noted.<\/p>\n<h2>Direct Send Amplifies Attacks<\/h2>\n<p>ReliaQuest noted that attacks that paired Axios with Microsoft\u2019s Direct Send achieved an even higher (70%) success rate in recent campaigns.<\/p>\n<p>That\u2019s because Direct Send is typically trusted by security tools by default.<\/p>\n<p>\u201cTogether, Direct Send and Axios form a highly efficient attack pipeline: Direct Send delivers phishing emails that appear legitimate, while Axios automates backend workflows like intercepting MFA tokens and authenticating stolen credentials,\u201d the report explained.<\/p>\n<p>\u201cThis seamless system allows attackers to operate at scale with minimal effort, blending into legitimate Axios traffic and evading detection.\u201d<\/p>\n<p>ReliaQuest urged\u00a0organizations to mitigate the threat of Axios abuse by:<\/p>\n<ul>\n<li>Disabling Direct Send if not needed. If it is used, organizations are urged to enforce stricter controls and route internal email activity through an email security gateway for threat inspection, like scanning for malicious QR codes, URLs\u00a0or PDF attachments<\/li>\n<li>Configure anti-spoofing policies on email gateways to block emails pretending to come from trusted sources<\/li>\n<li>Train all users, including executives, to recognize phishing emails with subject lines like \u201cMEM0,\u201d \u201c0VERDUE,\u201d and \u201cINV0ICE\u201d<\/li>\n<li>Block uncommon top-level domains like .es and .ru unless required for business reasons<\/li>\n<\/ul><\/div>\n","protected":false},"excerpt":{"rendered":"<p>Security experts have warned of a huge uptick in automated phishing activity abusing the Axios user agent and Microsoft\u2019s Direct Send feature. ReliaQuest claimed in a new report today that it observed a 241% increase in phishing activity using Axios between June and August 2025. Axios accounted for nearly a quarter (24%) of all malicious<\/p>\n","protected":false},"author":2,"featured_media":2751,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-2750","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized"],"featured_image_urls":{"full":["http:\/\/ft365.org\/wp-content\/uploads\/2025\/09\/2750-ca0104c5-9d43-4bd4-a68b-2c878b9f5662.jpg",300,300,false],"thumbnail":["http:\/\/ft365.org\/wp-content\/uploads\/2025\/09\/2750-ca0104c5-9d43-4bd4-a68b-2c878b9f5662-150x150.jpg",150,150,true],"medium":["http:\/\/ft365.org\/wp-content\/uploads\/2025\/09\/2750-ca0104c5-9d43-4bd4-a68b-2c878b9f5662.jpg",300,300,false],"medium_large":["http:\/\/ft365.org\/wp-content\/uploads\/2025\/09\/2750-ca0104c5-9d43-4bd4-a68b-2c878b9f5662.jpg",300,300,false],"large":["http:\/\/ft365.org\/wp-content\/uploads\/2025\/09\/2750-ca0104c5-9d43-4bd4-a68b-2c878b9f5662.jpg",300,300,false],"1536x1536":["http:\/\/ft365.org\/wp-content\/uploads\/2025\/09\/2750-ca0104c5-9d43-4bd4-a68b-2c878b9f5662.jpg",300,300,false],"2048x2048":["http:\/\/ft365.org\/wp-content\/uploads\/2025\/09\/2750-ca0104c5-9d43-4bd4-a68b-2c878b9f5662.jpg",300,300,false],"morenews-featured":["http:\/\/ft365.org\/wp-content\/uploads\/2025\/09\/2750-ca0104c5-9d43-4bd4-a68b-2c878b9f5662.jpg",300,300,false],"morenews-large":["http:\/\/ft365.org\/wp-content\/uploads\/2025\/09\/2750-ca0104c5-9d43-4bd4-a68b-2c878b9f5662.jpg",300,300,false],"morenews-medium":["http:\/\/ft365.org\/wp-content\/uploads\/2025\/09\/2750-ca0104c5-9d43-4bd4-a68b-2c878b9f5662.jpg",300,300,false],"crawlomatic_preview_image":["http:\/\/ft365.org\/wp-content\/uploads\/2025\/09\/2750-ca0104c5-9d43-4bd4-a68b-2c878b9f5662-146x146.jpg",146,146,true]},"author_info":{"display_name":"henry","author_link":"http:\/\/ft365.org\/index.php\/author\/henry\/"},"category_info":"<a href=\"http:\/\/ft365.org\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","_links":{"self":[{"href":"http:\/\/ft365.org\/index.php\/wp-json\/wp\/v2\/posts\/2750","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/ft365.org\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/ft365.org\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/ft365.org\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"http:\/\/ft365.org\/index.php\/wp-json\/wp\/v2\/comments?post=2750"}],"version-history":[{"count":0,"href":"http:\/\/ft365.org\/index.php\/wp-json\/wp\/v2\/posts\/2750\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"http:\/\/ft365.org\/index.php\/wp-json\/wp\/v2\/media\/2751"}],"wp:attachment":[{"href":"http:\/\/ft365.org\/index.php\/wp-json\/wp\/v2\/media?parent=2750"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/ft365.org\/index.php\/wp-json\/wp\/v2\/categories?post=2750"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/ft365.org\/index.php\/wp-json\/wp\/v2\/tags?post=2750"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}