How legitimate cloud platforms enable phishers to bypass MFA
Threat actors are increasingly leveraging legitimate cloud platforms – like Cloudflare, Vercel, Netlify, and GitHub Pages – to conduct sophisticated phishing attacks. These attacks utilize multi-stage adversary-in-the-middle (AitM) techniques, combined with browser-in-the-browser (BitB) spoofing, to hijack MFA sessions and steal credentials. The ease of use, generous free tiers, and built-in evasion capabilities of these platforms make them ideal for deploying complex phishing campaigns at scale. The analysis reveals a significant trend of phishing URLs hosted across these services, highlighting the need for layered security approaches beyond traditional HTTPS checks.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data
