Hackers Use Cloudflare Human Check to Hide Microsoft 365 Phishing Pages
ID: e7d00406-ade0-5399-9a19-2670f98d10a7
STIX ID: report--e7d00406-ade0-5399-9a19-2670f98d10a7
Feed Name: HackRead
Threat Score
Attackers are abusing Cloudflare Turnstile to present fake Microsoft 365 login pages that selectively serve phishing content to human visitors while hiding from security scanners and known security-related IPs. The campaign uses location checks via api.ipify.org, a custom VM-based obfuscation function (e_d007dc), and a reused static sitekey observed across multiple domains; researchers tied infrastructure to Namecheap registrations and mail servers such as jellyfish.systems.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
