New Tricks in the Phishing Playbook: Cloudflare Workers, HTML Smuggling, GenAI
ID: 3e945f49-e786-54c1-a9eb-1dc20f377223
STIX ID: report--3e945f49-e786-54c1-a9eb-1dc20f377223
Feed Name: The Hacker News
Threat Score
Researchers report a rise in phishing campaigns that use Cloudflare Workers as transparent AitM proxies and HTML smuggling to serve fake login pages and capture credentials and MFA codes for Microsoft 365, Gmail, Yahoo!, and webmail; campaigns span multiple sectors and regions, leverage PhaaS toolkits (e.g., Greatness), employ DNS tunneling for tracking, and distribute info-stealers and RATs via malvertising and oversized attachments.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
