logo

How legitimate cloud platforms enable phishers to bypass MFA

ID: b3858b9b-64ab-57a6-b94b-0e1c20400eee

STIX ID: report--b3858b9b-64ab-57a6-b94b-0e1c20400eee

Feed Name: Securelist by Kaspersky

Threat Score
78/100

Date Published: 2026-08-04

Date Updated: 2026-08-06

Author: Olga Altukhova

...
...

This report analyzes a widespread, multi-stage phishing campaign (Aug 2025–Jul 2026) that leverages reputable cloud and decentralized platforms to host phishing flows: stage 1 harvests emails via disposable relays and URL hashes, stage 2 registers service workers to create a transparent proxy (Ultraviolet) that intercepts traffic, and stage 3 uses a BitB (browser-in-the-browser) UI to capture credentials and MFA tokens. Telemetry shows hundreds of thousands of phishing pages and hundreds of thousands of unique third-level domains abused across platforms (top domains include pages.dev, vercel.app, github.io, netlify.app, ipfs gateways), and the report recommends layered defenses beyond reputation-based blocking, user awareness, and content-based detection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.