• Home  
  • Kaspersky detects over 209,000 phishing attacks abusing trusted cloud platforms
- Enterprise Technology - News

Kaspersky detects over 209,000 phishing attacks abusing trusted cloud platforms

Cybersecurity company Kaspersky has uncovered more than 209,000 phishing attacks over the past 12 months that exploited legitimate cloud services such as Cloudflare Workers, Vercel, Netlify, GitHub Pages, and IPFS to steal credentials and bypass security protections. According to Kaspersky researchers, cybercriminals are increasingly leveraging trusted cloud platforms to host phishing infrastructure, making malicious campaigns […]

Cybersecurity company Kaspersky has uncovered more than 209,000 phishing attacks over the past 12 months that exploited legitimate cloud services such as Cloudflare Workers, Vercel, Netlify, GitHub Pages, and IPFS to steal credentials and bypass security protections.

According to Kaspersky researchers, cybercriminals are increasingly leveraging trusted cloud platforms to host phishing infrastructure, making malicious campaigns more difficult to detect and block. The attacks often target Microsoft 365 users through sophisticated, multi-stage phishing schemes that can capture usernames, passwords, multi-factor authentication (MFA) codes, and session cookies.

The attack chain typically begins with a phishing email that directs victims to a fake “anti-bot” verification page. Users are asked to enter their corporate email address through a fraudulent CAPTCHA process, which is then passed through a Cloudflare Workers-hosted page. Victims subsequently encounter a legitimate CAPTCHA before being redirected to a fake Microsoft Office 365 login page.

Researchers found that attackers are increasingly using the Browser-in-the-Browser (BiTB) technique, which mimics a genuine browser pop-up window complete with realistic address bars and controls. This method creates the illusion of a legitimate Microsoft login page while secretly capturing credentials entered by the victim.

Kaspersky noted that the campaign employed an Adversary-in-the-Middle (AiTM) approach, allowing attackers to proxy traffic between the victim and the real Microsoft service. This enables threat actors to intercept login credentials, MFA tokens, and active session cookies, potentially granting unauthorized access even when multi-factor authentication is enabled.

“Attackers actively exploit legitimate services due to their reputation, free plans, and tools that they can exploit,” said Olga Altukhova, cybersecurity expert at Kaspersky. She added that the combination of Browser-in-the-Browser and Adversary-in-the-Middle techniques demonstrates how phishing attacks are becoming increasingly sophisticated.

To reduce risk, Kaspersky advises users to avoid entering personal information into CAPTCHA forms, verify website domains through the browser’s address bar, remain cautious of unexpected login requests, keep browsers updated, and deploy security solutions capable of analyzing scripts and dynamic web content rather than relying solely on domain reputation.

The findings highlight the growing challenge facing cybersecurity teams as threat actors increasingly abuse legitimate cloud infrastructure to evade detection and compromise enterprise accounts.

Email Us

For inquiries, press releases, and partnership request, get in touch with us at: info.aitimes.ph@gmail.com.

Contact: 0956-344-3286

AI Times  @2026. All Rights Reserved.