How legitimate cloud platforms enable phishers to bypass MFA


Threat actors are increasingly exploiting legitimate cloud services to evade detection and streamline the deployment of their scam infrastructure. Cloud hosting services and decentralized networks have become primary platforms for hosting phishing pages and sites. Throughout 2025 and 2026, Kaspersky researchers have observed phishing operators steadily migrate toward platforms like Cloudflare Workers, Vercel, Netlify, GitHub Pages, and IPFS. This post analyzes the mechanics of a real-life adversary-in-the-middle (AitM) attack in a cloud environment and presents detailed statistics on the platforms and domains phishers abuse most frequently.

Read more…
Source:  Kaspersky


Sign up for the Cyber Security Review Newsletter
The latest cyber security news and insights delivered right to your inbox


Related:

  • ‘Ice phishing’ on the blockchain

    February 16, 2022

    The technologies that connect us are continually advancing, and while this brings tremendous new capabilities to users, it also opens new attack surfaces for adversaries and abusers. Social engineering represents a class of threats that has extended to virtually every technology that enables human connection. Our recent analysis of a phishing attack connected to the ...

  • Suspected espionage in Palestine highlights spread of hacking skills

    February 16, 2022

    A wave of recent espionage activity from suspected Palestinian hackers is the latest evidence that wealthy spy agencies no longer are the sole operators of malware that covertly vacuums up victims’ data. A shadowy group has targeted governments in the Middle East, a state-affiliated airline and foreign policy think tanks as part of a “highly targeted” ...

  • Chrome Zero-Day Under Active Attack – Patch ASAP

    February 15, 2022

    Google on Monday issued 11 security fixes for its Chrome browser, including a high-severity zero-day bug that’s actively being jumped on by attackers in the wild. In a brief update, Google described the weakness, tracked as CVE-2022-0609, as a use-after-free vulnerability in Chrome’s Animation component. This kind of flaw can lead to all sorts of misery, ...

  • Warning over mysterious hackers that have been targeting aerospace and defence industries for years

    February 15, 2022

    An unknown criminal hacking group is targeting organisations in the aviation, aerospace, defence, transportation and manufacturing industries with trojan malware, in attacks that researchers say have been going on for years. Dubbed TA2541 and detailed by cybersecurity researchers at Proofpoint, the persistent cyber-criminal operation has been active since 2017 and has compromised hundreds of organisations across ...

  • SMS PVA Services’ Use of Infected Android Phones Reveals Flaws in SMS Verification

    February 15, 2022

    There has been an increase in short message service (SMS) phone-verified account (PVA) services in the last two years. SMS PVA services provide alternative mobile numbers that customers can use to register for online services and platforms. These types of services help circumvent the SMS verification mechanisms widely used by online platforms and services to ...

  • Squirrelwaffle, Microsoft Exchange Server vulnerabilities exploited for financial fraud

    February 15, 2022

    The combination of Squirrelwaffle, ProxyLogon, and ProxyShell against Microsoft Exchange Servers is being used to conduct financial fraud through email hijacking. On Tuesday, researchers from Sophos revealed a recent incident in which a Microsoft Exchange Server, which had not been patched to protect it against a set of critical vulnerabilities disclosed last year, was targeted to ...