logo

Threat Actors Abuse Microsoft & Google Platforms to Attack Enterprise Users

ID: 8d64d2d6-3582-5605-aa58-580bce3926ad

STIX ID: report--8d64d2d6-3582-5605-aa58-580bce3926ad

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2026-02-04

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

**Executive Summary:** Enterprise-targeted phishing campaigns are increasingly hosted on trusted cloud platforms (Microsoft Azure Blob, Google Firebase, AWS CloudFront) and delivered via AiTM phishing kits (Tycoon2FA, Sneaky2FA, EvilProxy) that proxy victims to legitimate authentication services to capture credentials and session tokens — even bypassing MFA; these Phishing-as-a-Service operations scale rapidly and evade traditional indicators, requiring continuous threat intelligence, behavioral analysis, and interactive sandboxing to detect.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.