Executive Summary
In 2026, threat actors increasingly exploited legitimate cloud services to host phishing sites, leveraging platforms like Cloudflare Workers, Vercel, Netlify, GitHub Pages, and IPFS. This approach allowed attackers to bypass traditional security measures, as phishing pages hosted on reputable domains appeared trustworthy to victims. The use of these platforms enabled the rapid deployment of multi-stage adversary-in-the-middle (AitM) attacks, effectively capturing multi-factor authentication (MFA) sessions and compromising user accounts.
This trend underscores a significant shift in cybercriminal tactics, highlighting the need for enhanced detection mechanisms that go beyond domain reputation. The widespread abuse of trusted cloud services for phishing campaigns necessitates a reevaluation of current security strategies to effectively counteract these sophisticated threats.
Why This Matters Now
The exploitation of legitimate cloud platforms for phishing attacks represents a critical evolution in cyber threats, making traditional security measures less effective. Organizations must adapt by implementing advanced detection techniques and educating users about the risks associated with seemingly trustworthy domains.
Attack Path Analysis
The attack began with a phishing email leading to a fake CAPTCHA page on a compromised website, harvesting the victim's email address. The victim was then redirected to a Cloudflare Workers-hosted page that registered a service worker, establishing a transparent proxy to intercept and modify network requests. This proxy facilitated an adversary-in-the-middle attack, capturing credentials and session tokens entered into a spoofed login form. The attackers used the stolen session tokens to access the victim's accounts, exfiltrating sensitive data. The attack concluded with the attackers maintaining access to the compromised accounts, potentially leading to further exploitation or data breaches.
Kill Chain Progression
Initial Compromise
Description
The attacker sends a phishing email containing a link to a fake CAPTCHA page hosted on a compromised legitimate website, tricking the victim into entering their email address.
MITRE ATT&CK® Techniques
Phishing: Spearphishing Link
Web Service
Compromise Accounts: Cloud Accounts
Exfiltration Over Web Service: Exfiltration to Cloud Storage
Valid Accounts: Cloud Accounts
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Ensure that security policies and operational procedures for security monitoring and testing are documented, in use, and known to all affected parties.
Control ID: 6.4.3
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA – ICT Risk Management Framework
Control ID: Article 5
CISA ZTMM 2.0 – Identity and Access Management
Control ID: 3.1
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Financial Services
High-value targets for MFA bypass phishing using cloud platforms; extensive regulatory compliance requirements vulnerable to credential harvesting and session hijacking attacks.
Banking/Mortgage
Critical exposure to adversary-in-the-middle attacks targeting customer authentication; trusted cloud domains enable sophisticated phishing bypassing traditional security controls and defenses.
Information Technology/IT
Cloud infrastructure dependencies create attack surfaces via legitimate platforms; service workers and reverse proxies compromise zero trust architectures and network segmentation controls.
Health Care / Life Sciences
HIPAA compliance violations through compromised authentication systems; patient data exfiltration risks via encrypted traffic interception and lateral movement through healthcare networks.
Sources
- How legitimate cloud platforms enable phishers to bypass MFAhttps://securelist.com/cloud-platforms-in-phishing/120832/Verified
- Cloudflare developer domains increasingly abused by threat actorshttps://www.techradar.com/pro/security/cloudflares-developer-domains-increasingly-abused-by-threat-actorsVerified
- Cloudflare-Fronted Phishing in 2026 — How Workers, Pages, Tunnels, and R2 Became Default Phishing Infrastructurehttps://ringsafe.in/cloudflare-fronted-phishing-in-2026-how-workers-pages-tunnels-and-r2-became-default-phishing-infrastructure/Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Aviatrix Zero Trust CNSF is pertinent to this incident as it could have constrained the attacker's ability to move laterally and exfiltrate data by enforcing strict segmentation and identity-based access controls.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: While Aviatrix CNSF primarily focuses on internal network segmentation and control, it could have limited the attacker's ability to exploit internal resources post-compromise.
Control: Zero Trust Segmentation
Mitigation: Aviatrix Zero Trust Segmentation could have limited the attacker's ability to escalate privileges by enforcing strict access controls and segmenting network traffic.
Control: East-West Traffic Security
Mitigation: Aviatrix East-West Traffic Security could have limited the attacker's ability to move laterally by enforcing strict segmentation and monitoring internal traffic.
Control: Multicloud Visibility & Control
Mitigation: Aviatrix Multicloud Visibility & Control could have limited the attacker's ability to maintain command and control by providing comprehensive monitoring and control over network traffic.
Control: Egress Security & Policy Enforcement
Mitigation: Aviatrix Egress Security & Policy Enforcement could have limited the attacker's ability to exfiltrate data by controlling and monitoring outbound traffic.
Aviatrix Zero Trust CNSF could have reduced the overall impact by limiting the attacker's ability to exploit additional resources and exfiltrate data.
Impact at a Glance
Affected Business Functions
- Email Communications
- User Authentication
- Access Control
Estimated downtime: N/A
Estimated loss: N/A
Potential exposure of user credentials and session tokens due to phishing attacks leveraging legitimate cloud services.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to limit the attacker's ability to move laterally within the network.
- • Deploy Egress Security & Policy Enforcement to monitor and control outbound traffic, preventing data exfiltration.
- • Utilize Threat Detection & Anomaly Response systems to identify and respond to suspicious activities in real-time.
- • Enforce Multi-Factor Authentication (MFA) to add an additional layer of security to user accounts.
- • Conduct regular security awareness training to educate users about phishing tactics and how to recognize them.



