logo

Cloud-Hosted Trap: Phishers Use Vercel & Telegram to Bypass Filters

ID: 28177b65-570a-5907-804e-c451e17c3d42

STIX ID: report--28177b65-570a-5907-804e-c451e17c3d42

Feed Name: securityonline.info

Threat Score
70/100

Date Published: 2026-02-06

Date Updated: 2026-04-23

Author: Ddos

...
...

X-Labs describes a multi-stage phishing campaign that delivers a first PDF via email (clean of malicious links), which links to a second PDF hosted on legitimate cloud infrastructure and ultimately redirects victims to a fake Dropbox login page; harvested credentials and system/location data are exfiltrated via a Telegram bot. The campaign highlights evasion techniques—using trusted cloud services and clean-looking emails—to bypass reputation- and link-based defenses and steal user credentials.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.