logo

Hackers Use Cloudflare Human Check to Hide Microsoft 365 Phishing Pages

ID: e7d00406-ade0-5399-9a19-2670f98d10a7

STIX ID: report--e7d00406-ade0-5399-9a19-2670f98d10a7

Feed Name: HackRead

Threat Score
60/100

Date Published: 2026-03-12

Date Updated: 2026-04-22

Author: Deeba Ahmed

...
...

Attackers are abusing Cloudflare Turnstile to present fake Microsoft 365 login pages that selectively serve phishing content to human visitors while hiding from security scanners and known security-related IPs. The campaign uses location checks via api.ipify.org, a custom VM-based obfuscation function (e_d007dc), and a reused static sitekey observed across multiple domains; researchers tied infrastructure to Namecheap registrations and mail servers such as jellyfish.systems.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.