logo

New Tricks in the Phishing Playbook: Cloudflare Workers, HTML Smuggling, GenAI

ID: 3e945f49-e786-54c1-a9eb-1dc20f377223

STIX ID: report--3e945f49-e786-54c1-a9eb-1dc20f377223

Feed Name: The Hacker News

Threat Score
72/100

Date Published: 2024-05-27

Date Updated: 2026-05-05

Author: [email protected] (The Hacker News)

...
...

Researchers report a rise in phishing campaigns that use Cloudflare Workers as transparent AitM proxies and HTML smuggling to serve fake login pages and capture credentials and MFA codes for Microsoft 365, Gmail, Yahoo!, and webmail; campaigns span multiple sectors and regions, leverage PhaaS toolkits (e.g., Greatness), employ DNS tunneling for tracking, and distribute info-stealers and RATs via malvertising and oversized attachments.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.