GhostFrame: The Stealthy Phishing Kit That’s Already Launched Over 1 Million Attacks
What Houston Businesses Need To Know About The GhostFrame Phishing Kit – The Two-Stage Phishing Attack That Bypasses Traditional Email Filters
Barracuda named GhostFrame in December 2025 as the first phishing framework built entirely around iframe abuse. For a Houston business on Microsoft 365 or Google Workspace, the danger is that the outer page looks clean.
The GhostFrame phishing kit is the first phishing framework Barracuda has seen built entirely around iframe abuse, and it has already powered more than 1 million attacks since September 2025. The outer page looks harmless. The theft happens in a window you cannot see.
Barracuda's threat analysts published the GhostFrame writeup on December 4, 2025. The short version: a phishing page that hides its real intent inside an iframe, a small embedded window that loads content from somewhere else. Security tools that scan the outer page find nothing wrong, because nothing on the outer page is wrong. The credential-stealing form lives on a second page, loaded invisibly, on a subdomain generated fresh for each target. CinchOps is a managed IT services provider based in Katy, Texas, serving small and mid-sized businesses across the Houston metro area, and this is the kind of kit that turns a routine-looking email into a Microsoft 365 account takeover before anyone notices.
What Is the GhostFrame Phishing Kit?
A phishing-as-a-service platform that weaponizes a browser feature every website uses.
GhostFrame is a phishing-as-a-service (PhaaS) kit that Barracuda first identified in September 2025 and linked to over 1 million attacks by December. It rents access to non-technical criminals and hides its credential theft inside an iframe, which is why the outer phishing page passes most static scanners.
Phishing-as-a-service means the attack tooling is a product. Someone else builds and maintains the kit; the buyer just points it at targets and collects stolen logins. That model is why GhostFrame spread so fast - the barrier to running a convincing Microsoft 365 or Google login trap dropped to a rental fee. Barracuda found two code variants, one obfuscated for stealth and one readable with developer comments, which points to an organized effort selling to attackers at different skill levels. The kit can render pixel-perfect copies of Microsoft 365 and Google sign-in pages as images, so what the victim sees is indistinguishable from the real thing.
- It is the first of its kind. Iframe abuse in phishing is not new, but GhostFrame is the first complete framework built around it, per Barracuda's December 2025 report.
- It is a rented weapon. The PhaaS model means several criminal groups run GhostFrame at once, which makes attribution hard and the reach wide.
- It fakes the pages you trust most. Microsoft 365 and Google Workspace login screens are the primary lures, delivered as images so text-based checks miss them.
How Does GhostFrame's iframe Trick Evade Detection?
A two-stage split that keeps the dangerous half out of every scanner's view.
GhostFrame splits the attack in two. The outer HTML page carries no phishing markers and passes inspection. A hidden iframe then loads the real credential-stealing page from a fresh subdomain, generated per victim and rotated mid-session, so blacklisting the domain rarely works.
Think of it as a clean storefront with the crime happening in a back room the inspector never enters. The outer page uses light obfuscation and looks like an ordinary file. Embedded pointers quietly send the browser to a second page through a hidden iframe, and that second page holds the login forms - concealed inside a blob URI image-streaming feature meant for large files, which static scanners are not built to read. A new random subdomain per target makes blacklists useless, and the subdomains can rotate during a single session. A fallback iframe keeps the attack alive even if JavaScript is blocked. The scoreboard below lays out why this design is so hard to stop.
The kit also fights the analysts trying to study it. It blocks right-clicks, disables the F12 developer-tools key, kills shortcuts like Ctrl+U and Ctrl+S, and even disables the Enter key to stop anyone saving or examining the page. By locking down both mouse and keyboard, GhostFrame leaves almost no normal way to inspect what it is doing. That is a deliberate design choice, not an accident, and it is why the usual "look at the source" advice falls flat here.
The delivery is ordinary on purpose. Victims get emails built to feel routine or urgent: fake contract notices ("Secure Contract & Proposal Notification"), spoofed HR notes ("Annual Review Reminder"), fake invoices, and account-security alerts ("Password Reset Request"). Those are the exact subject lines a busy Houston office clicks without a second thought.
Why Are Houston SMBs Squarely in GhostFrame's Range?
The kit targets the tools and gaps common to small and mid-sized firms.
GhostFrame targets Microsoft 365 and Google Workspace logins, the two platforms nearly every Houston SMB runs on. Small firms without dedicated security staff, strong email filtering, or regular awareness training sit at the highest risk, because the kit is built to slip past exactly those missing layers.
Cybercriminals do not pick targets by zip code. A GhostFrame operator renting the kit blasts it at whatever address list they bought, and a Katy engineering firm lands in the same batch as a Fortune 500. What decides the outcome is your defense depth, not your location. The higher-risk profile Barracuda describes reads like a checklist of small-business reality: no dedicated IT security staff, Microsoft 365 or Google Workspace for email and login, sensitive financial or personal data on hand, thin email filtering, and no steady security awareness training. That is the setup for a lot of law firms, CPA practices, and construction offices across Sugar Land and Cypress. In 35 years doing this, the pattern I trust most is boring but true: the businesses that get hit are almost never the ones with the newest firewall - they are the ones where one person, one tired afternoon, typed a password into a page that looked right.
- Your login page is the prize. Microsoft 365 and Google Workspace credentials open email, files, and often the path to a wire-fraud request in the CEO's name.
- MFA is the backstop that still works. Even if credentials are stolen, multi-factor authentication on every business account blocks most account takeovers cold.
- People are the last layer the kit cannot bypass. A trained employee who checks the real URL and reports the "embedded, half-loaded" page is the detection GhostFrame is designed to defeat.
GhostFrame is a warning about where phishing is going. The kit is rented, the fake page is an image, and the theft happens in a frame you never see. You cannot filter your way out of that alone. The businesses that stay safe are the ones that layered MFA, email security, and trained people together before the email arrived - not after.
Layered Defense Against Rented Phishing Kits
GhostFrame is built to slip past single-filter defenses. CinchOps gives Houston-area businesses the email security, MFA enforcement, monitoring, and awareness training that stop credential theft even when the outer page looks clean. It is the core of our cybersecurity and managed IT services.
Explore CinchOps cybersecurity →How CinchOps Helps Houston Businesses Defend Against GhostFrame
CinchOps is a managed IT services provider based in Katy, Texas, serving small and mid-sized businesses across the Houston metro area, focused on the layered defenses a single email filter cannot provide against kits like GhostFrame.
CinchOps specializes in cybersecurity, network security, managed IT support, VoIP, and SD-WAN for businesses with 10-200 employees. GhostFrame is built to defeat the one-tool defenses most small firms rely on, so we close the gaps it aims for:
- Advanced email security. Enterprise-grade filtering that inspects for suspicious iframes and malicious redirects in HTML emails and landing pages, not just the outer page.
- Multi-factor authentication everywhere. MFA on every business account, so a stolen Microsoft 365 or Google password does not become an account takeover.
- Employee awareness training. Ongoing coaching so your team spots urgency-bait subject lines and the "embedded, half-loaded" login pages GhostFrame relies on.
- 24/7 monitoring and response. We watch for login anomalies and unusual redirect patterns, and we move fast to contain a compromise if one slips through.
GhostFrame will not be the last rented phishing kit, and the next one will hide somewhere new. If you run a business in Houston or Katy - or run a law firm, CPA practice, or construction firm on Microsoft 365 - and you are not sure your defenses go deeper than one filter, talk to CinchOps and we will tell you straight where the gaps are.
Frequently Asked Questions
What is the GhostFrame phishing kit?
GhostFrame is a phishing-as-a-service kit that Barracuda identified in September 2025 and linked to more than 1 million attacks by December 2025. It hides its credential-stealing page inside a hidden iframe, so the outer phishing page carries no obvious markers and slips past security tools that only scan the surface.
Why is GhostFrame so hard to detect?
GhostFrame splits the attack in two: a clean outer page and a hidden iframe that loads the real login trap from a fresh subdomain generated per victim. The subdomains rotate mid-session to defeat blacklisting, and credential forms hide inside a blob URI image feature that static scanners are not built to read.
Who is at risk from GhostFrame?
Any organization that uses email is a potential target, but risk is highest for small and mid-sized businesses without dedicated security staff, those on Microsoft 365 or Google Workspace, and firms lacking strong email filtering or regular awareness training. Houston-area SMBs face the same exposure as businesses anywhere.
How can a Houston SMB defend against GhostFrame?
Use layered defense, not one filter. Enable multi-factor authentication on every account, deploy email security that inspects for suspicious iframes and redirects, keep browsers updated, and train employees to verify URLs and report "embedded" or half-loaded login pages. A managed IT provider can run all of it at SMB scale.
Does multi-factor authentication stop GhostFrame?
MFA is the strongest single backstop. Even when GhostFrame steals a Microsoft 365 or Google password, multi-factor authentication blocks most account takeovers because the attacker still lacks the second factor. It is not perfect against every technique, so pair it with email filtering, monitoring, and user training for real protection.