Categories: Cyber Security News

Hackers Abusing Legitimate Cloud and CDN Platforms to Host Phishing Kits

Threat actors are increasingly using trusted cloud and content delivery network platforms to host phishing kits, creating major detection challenges for security teams.

Unlike traditional phishing campaigns that rely on newly registered suspicious domains, these attacks use legitimate infrastructure from providers like Google, Microsoft Azure, and AWS CloudFront.

This approach allows hackers to bypass many security filters because the domains appear trustworthy at first glance.

The shift toward cloud-based phishing infrastructure represents a concerning evolution in social engineering attacks.

Victims encounter familiar domain names from well-known technology companies, making them more likely to enter sensitive credentials.

Network monitoring tools also struggle to flag these activities since they see ordinary HTML content loading from established cloud services rather than suspicious traffic patterns.

This technique specifically targets enterprise users in several campaigns, filtering out free email accounts to focus on corporate credentials.

Any.Run researchers identified this growing pattern while analyzing multiple phishing kit families. The analysis revealed that Tycoon phishing kit operates from Microsoft Azure Blob Storage, specifically using the domain alencure[.]blob[.]core[.]windows[.]net.

https://twitter.com/anyrun_app/status/2011756689024815184?ref_src=twsrc%5Etfw

Sneaky2FA phishing kit was found on Firebase Cloud Storage at firebasestorage[.]googleapis[.]com and AWS CloudFront at cloudfront[.]net, using fake Microsoft 365 login pages to harvest corporate account credentials.

EvilProxy phishing kit leverages Google Sites at sites[.]google[.]com to host its malicious pages.

Detection and Response Challenges

Security teams face unique obstacles when dealing with cloud-hosted phishing infrastructure.

Traditional domain reputation checks fail because the hosting platforms themselves are legitimate services used by countless organizations for valid purposes.

Most security vendors classify these cloud domains as safe, which is technically accurate. The malicious activity exists in the content being served, not the infrastructure itself.

The solution requires behavioral analysis rather than simple domain checks. Security platforms need to examine how users interact with these cloud-hosted pages and identify suspicious patterns in real-time.

Any.Run Sandbox demonstrates this capability by exposing these threats in under 60 seconds, reducing both mean time to detect and mean time to respond.

Organizations should implement threat intelligence lookups that specifically search for abuse patterns on Microsoft Azure Blob Storage, Firebase Cloud Storage, and Google Sites platforms.

Related indicators of compromise include mphdvh[.]icu, kamitore[.]com, aircosspascual[.]com, and Lustefea[.]my[.]id.

Follow us on Google NewsLinkedIn, and X to Get More Instant UpdatesSet CSN as a Preferred Source in Google.

The post Hackers Abusing Legitimate Cloud and CDN Platforms to Host Phishing Kits appeared first on Cyber Security News.

rssfeeds-admin

Recent Posts

Netflix’s The Boroughs Showrunners Explain the End of Season 1, and What May Happen in Season 2

This article contains spoilers for The Boroughs Season 1, including the Season 1 finale.There goes…

56 minutes ago

These LEGO Batman Sets Unlock DLC Vehicles in LEGO Batman: Legacy of the Dark Knight

In the new LEGO Batman: Legacy of the Dark Knight game, you play a "greatest…

58 minutes ago

Torneos Upgrades Multichannel Playout With Imagine’s Versio

The post Torneos Upgrades Multichannel Playout With Imagine’s Versio appeared first on TV News Check.

2 hours ago

Fuse Media Taps iSpot As Official Measurement Provider For FAST & CTV Inventory

The post Fuse Media Taps iSpot As Official Measurement Provider For FAST & CTV Inventory…

2 hours ago

Ross Video to Invest C$122.5 Million To Expand Manufacturing & R&D

The post Ross Video to Invest C$122.5 Million To Expand Manufacturing & R&D appeared first…

2 hours ago

This website uses cookies.