Phishers are hijacking legitimate cloud infrastructure

Threat actors are increasingly exploiting legitimate cloud platforms (Cloudflare Workers, Vercel, Netlify, GitHub Pages) to host sophisticated phishing infrastructure, leveraging platform reputation and built-in anonymity features to evade detection at scale. These multi-stage attacks use adversary-in-the-middle techniques combined with service workers to intercept credentials and MFA sessions, making traditional domain-blocking strategies ineffective and requiring security teams to shift toward advanced content-based detection methods. For IT organizations, this represents a critical gap where trusted cloud vendors become attack vectors, demanding enhanced email security, user authentication monitoring, and closer vendor relationship management to identify and respond to account compromise campaigns.

Hacker News3 min read
Read full article
Phishers are hijacking legitimate cloud infrastructure

Read the full story at Hacker News →