securelist · Crawled Aug 4, 2026

How legitimate cloud platforms enable phishers to bypass MFA

11 IoCs
Read original article ↗

AI Summary

Threat actors are leveraging legitimate cloud platforms such as Cloudflare Workers, Vercel, Netlify, GitHub Pages, and IPFS to host phishing infrastructure and bypass multi-factor authentication (MFA). The attack uses a multi-stage adversary-in-the-middle (AitM) technique involving contact harvesting, transparent proxy initialization via service workers, and browser-in-the-browser (BitB) spoofing to intercept credentials and session tokens. Phishing pages are hosted on trusted domains with good reputations, making detection difficult and enabling large-scale, low-cost deployment of malicious sites.

AI-extracted · verify before operational use

Indicators of Compromise 11 extracted

Type Value Detail
Domain t[REDACTED]e[.]com Details →
Domain workers[.]dev Details →
Domain pages[.]dev Details →
Domain vercel[.]app Details →
Domain github[.]io Details →
Domain netlify[.]app Details →
Domain dweb[.]link Details →
Domain ipfs[.]io Details →
Domain wixstudio[.]com Details →
Domain webflow[.]io Details →
Domain azurewebsites[.]net Details →