M ore than 390,000 phishing attacks have exploited legitimate cloud platforms over the past 12 months, according to new research from Kaspersky.
CLOUD SECURITY
Kaspersky warns cloud platforms are being exploited in phishing attacks
Kaspersky research has identified more than 390,000 phishing attacks using legitimate cloud platforms during the past 12 months.
M ore than 390,000 phishing attacks have exploited legitimate cloud platforms over the past 12 months, according to new research from Kaspersky.
The campaigns use trusted services including Cloudflare Workers, Vercel, Netlify, GitHub Pages and IPFS to support sophisticated multistage attacks designed to steal credentials and bypass Multi-Factor Authentication( MFA).
According to Kaspersky, one campaign begins with attackers posing as trusted contacts and attempting to persuade victims to log into their Microsoft accounts through a phishing link.
After following the link, victims are directed to a fake anti-bot page and asked to complete a fraudulent CAPTCHA by entering their corporate email address. Rather than verifying whether the visitor is human, the page captures the email address before redirecting the victim to a Cloudflare Workers subdomain.
A second CAPTCHA is then displayed before the victim encounters what appears to be a standard Microsoft 365 login window.
Kaspersky said attackers use a Browser-in-the-Browser( BiTB) technique to reproduce elements including the address bar and window controls. The fraudulent window captures the victim’ s username, password, MFA code and session cookies before redirecting them to an error page intended to conceal the compromise.
“ Attackers actively exploit legitimate services due to their reputation, free plans, and tools that they can exploit. What’ s more, in the example that we investigated in the report, phishers were able to create a multi-stage Adversary-in-the-Middle attack, proxying all traffic from what looked like a legitimate Microsoft website and combining it with Browser-in-the-Browser techniques. This shows how phishing techniques are becoming more and more sophisticated,” commented Olga Altukhova, Cybersecurity Expert at Kaspersky.
Attackers actively exploit legitimate services due to their reputation, free plans, and tools that they can exploit.
Kaspersky advised users to treat CAPTCHA requests for personal information as a potential warning sign and remain cautious about unexpected login requests, even when they appear to originate from trusted domains.
Users should also verify the URL displayed in the main browser address bar, as BiTB attacks can imitate browser windows but cannot alter the genuine domain shown by the browser. Kaspersky also recommended keeping browsers and security extensions updated.
A fake CAPTCHA used to collect the victim’ s email and sort bots
A website with a Microsoft sign-in form that looks legitimate, but is secretly proxying traffic to the attackers.
WWW. INTELLIGENTCISO. COM 31