Kaspersky warns that popular Cloud Platforms have been used in over 200,000 Phishing Attacks

Kaspersky warns that popular Cloud Platforms have been used in over 200,000 Phishing Attacks

New Kaspersky research into phishing activity leveraging legitimate cloud platforms has revealed over 209,000 such attacks have been carried out in the last 12 months alone. These campaigns leverage trusted services such as Cloudflare Workers, Vercel, Netlify, GitHub Pages and IPFS to carry out sophisticated multi-stage attacks and even bypass multi-factor authentication. Detailed information is available in a new report on Securelist.

The phishing campaign begins when an attacker — potentially posing as a trusted contact — crafts a pretext to lure the victim into logging into their Microsoft account via a phishing link. The link is often delivered via email, and after clicking on it the user lands on an alleged “anti-bot” page. There, the victim is prompted to complete the first fake CAPTCHA by entering their corporate email address. Rather than validating human interaction, this step harvests the email and redirects the user to a *.workers.dev* URL automatically provided by Cloudflare, passing the email address in the URL hash so that the next page can receive it without accessing the attacker’s server.

On the next page, which is hosted under a free Cloudflare Workers subdomain, the users passes another CAPTCHA, this time a genuine one which is not integrated into the HTML code, but is integrated into the page dynamically, thus making it more difficult for security solutions to detect.

Finally, the user is presented with what appears to be a standard Office 365 login window-created using the Browser-in-the-Browser (BiTB) technique – complete with an authentic-looking address bar and window controls. In reality this is a floating window that passes all entered information to the attackers. As the victim enters their username, password and multi-factor authentication code, the injected script captures all credentials and session cookies and redirects them to a generic error page to conceal the breach.

Attackers actively exploit legitimate services due to their reputation, free plans, and tools that they can exploit. What’s more, in the example that we investigated in the report, phishers were able to create a multi-stage Adversary-in-the-Middle attack, proxying all traffic from what looked like a legitimate Microsoft website and combining it with Browser-in-the-Browser techniques. This shows how phishing techniques are becoming more and more sophisticated,” commented Olga Altukhova, cybersecurity expert at Kaspersky.

To stay safe, Kaspersky has provided its advice and recommendations: CAPTCHAs typically do not ask for personal information—such as your email address. If a verification step requires you to submit personal data to prove you're not a robot, that is a strong red flag for phishing or fraud. Be cautious with unexpected login requests, even if they originate from trusted domains or display valid SSL certificates. Verify the URL in the main browser’s window address bar – Browser-in-the-Browser attacks can spoof window chrome or pop-up but cannot change the actual domain shown by the browser itself. Keep browsers and security extensions up to date. Use trusted security solutions that inspect page scripts and dynamic assets, not just domain reputation.

You Must be Registered Or Logged in To Comment Log In?