securelist · Crawled Aug 4, 2026
How legitimate cloud platforms enable phishers to bypass MFA
11 IoCs
Read original article ↗
AI Summary
Threat actors are leveraging legitimate cloud platforms such as Cloudflare Workers, Vercel, Netlify, GitHub Pages, and IPFS to host phishing infrastructure and bypass multi-factor authentication (MFA). The attack uses a multi-stage adversary-in-the-middle (AitM) technique involving contact harvesting, transparent proxy initialization via service workers, and browser-in-the-browser (BitB) spoofing to intercept credentials and session tokens. Phishing pages are hosted on trusted domains with good reputations, making detection difficult and enabling large-scale, low-cost deployment of malicious sites.
AI-extracted · verify before operational use
Indicators of Compromise 11 extracted
| Type | Value | Detail |
|---|---|---|
| Domain | t[REDACTED]e[.]com | Details → |
| Domain | workers[.]dev | Details → |
| Domain | pages[.]dev | Details → |
| Domain | vercel[.]app | Details → |
| Domain | github[.]io | Details → |
| Domain | netlify[.]app | Details → |
| Domain | dweb[.]link | Details → |
| Domain | ipfs[.]io | Details → |
| Domain | wixstudio[.]com | Details → |
| Domain | webflow[.]io | Details → |
| Domain | azurewebsites[.]net | Details → |