Saturday, 22 August 2026
Nigeria Communications Week
E-Business

Firm Warns As Popular Cloud Platforms Have Been Used in Over 390,000 Phishing Attacks

Chike Onwuegbuchi20 Aug 20260 Comments
Firm Warns As Popular Cloud Platforms Have Been Used in Over 390,000 Phishing Attacks
Kindly share this post

New Kaspersky research into phishing activity leveraging legitimate cloud platforms has revealed over 390,000 such attacks have been carried out in the last 12-months alone.

New Kaspersky research into phishing activity leveraging legitimate cloud platforms has revealed over 390,000 such attacks have been carried out in the last 12-months alone.

These campaigns leverage trusted services such as Cloudflare Workers, Vercel, Netlify, GitHub Pages and IPFS to carry out sophisticated multi-stage attacks and even bypass multi-factor authentication. Detailed information is available in a new report on Securelist.

The phishing campaign begins when an attacker — potentially posing as a trusted contact — crafts a pretext to lure the victim into logging into their Microsoft account via a phishing link. The link is often delivered via email, and after clicking on it the user lands on an alleged “anti-bot” page. 

There, the victim is prompted to complete the first fake CAPTCHA by entering their corporate email address. Rather than validating human interaction, this step harvests the email and redirects the user to a *.workers.dev* URL automatically provided by Cloudflare, passing the email address in the URL hash so that the next page can receive it without accessing the attacker’s server.

On the next page, which is hosted under a free Cloudflare Workers subdomain, the user passes another CAPTCHA, this time a genuine one which is not integrated into the HTML code, but is integrated into the page dynamically, thus making it more difficult for security solutions to detect.

Finally, the user is presented with what appears to be a standard Office 365 login window-created using the Browser-in-the-Browser (BiTB) technique – complete with an authentic-looking address bar and window controls. 

In reality this is a floating window that passes all entered information to the attackers. As the victim enters their username, password and multi-factor authentication code, the injected script captures all credentials and session cookies and redirects them to a generic error page to conceal the breach.

Attackers actively exploit legitimate services due to their reputation, free plans, and tools that they can exploit. What’s more, in the example that we investigated in the report, phishers were able to create a multi-stage Adversary-in-the-Middle attack, proxying all traffic from what looked like a legitimate Microsoft website and combining it with Browser-in-the-Browser techniques. This shows how phishing techniques are becoming more and more sophisticated,” commented Olga Altukhova, cybersecurity expert at Kaspersky.

C
Published by

Chike Onwuegbuchi

Trained and practicing journalist passionate about telecommunications, fintech, cybersecurity, and digital economy reporting.

More in E-Business