logo

Enterprise Phishing: How Attackers Abuse Trusted Microsoft & Google Platforms 

ID: da8ad718-7cf8-5df4-b9c7-765ef5125d82

STIX ID: report--da8ad718-7cf8-5df4-b9c7-765ef5125d82

Feed Name: ANY.RUN's Cybersecurity Blog

Threat Score
75/100

Date Published: 2026-02-03

Date Updated: 2026-04-26

Author: GridGuardGhoul

...
...

Enterprise phishing campaigns are increasingly hosted on legitimate cloud and CDN platforms (Cloudflare, Microsoft Azure, Google Firebase, AWS), enabling adversary-in-the-middle (AiTM) phishing kits like Tycoon2FA, Sneaky2FA, and EvilProxy to bypass traditional IOCs (IPs, TLS fingerprints, certs) and target corporate accounts and MFA, requiring continuous monitoring, interactive sandboxing, and threat intelligence to detect and mitigate.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.