Skip to main content

Kaspersky warns that popular cloud platforms have been used in over 390,000 phishing attacks

20 August 2026

New Kaspersky research into phishing activity leveraging legitimate cloud platforms has revealed over 390,000 such attacks have been carried out in the last 12-months alone. These campaigns leverage trusted services such as Cloudflare Workers, Vercel, Netlify, GitHub Pages and IPFS to carry out sophisticated multi-stage attacks and even bypass multi-factor authentication. Detailed information is available in a new report on Securelist.

The phishing campaign begins when an attacker — potentially posing as a trusted contact — crafts a pretext to lure the victim into logging into their Microsoft account via a phishing link. The link is often delivered via email, and after clicking on it the user lands on an alleged “anti-bot” page. There, the victim is prompted to complete the first fake CAPTCHA by entering their corporate email address. Rather than validating human interaction, this step harvests the email and redirects the user to a *.workers.dev* URL automatically provided by Cloudflare, passing the email address in the URL hash so that the next page can receive it without accessing the attacker’s server.

260820_1

A fake CAPTCHA used to collect the victim’s email and sort bots.

On the next page, which is hosted under a free Cloudflare Workers subdomain, the user passes another CAPTCHA, this time a genuine one which is not integrated into the HTML code, but is integrated into the page dynamically, thus making it more difficult for security solutions to detect. 

Finally, the user is presented with what appears to be a standard Office 365 login window-created using the Browser-in-the-Browser (BiTB) technique – complete with an authentic-looking address bar and window controls. In reality this is a floating window that passes all entered information to the attackers. As the victim enters their username, password and multi-factor authentication code, the injected script captures all credentials and session cookies and redirects them to a generic error page to conceal the breach.

260820_2

A website with a Microsoft sign-in form that looks legitimate, but is secretly proxying traffic to the attackers.

“Attackers actively exploit legitimate services due to their reputation, free plans, and tools that they can exploit. What’s more, in the example that we investigated in the report, phishers were able to create a multi-stage Adversary-in-the-Middle attack, proxying all traffic from what looked like a legitimate Microsoft website and combining it with Browser-in-the-Browser techniques. This shows how phishing techniques are becoming more and more sophisticated,” commented Olga Altukhova, cybersecurity expert at Kaspersky.

To stay safe, Kaspersky has provided its advice and recommendations:

  • CAPTCHAs typically do not ask for personal information — such as your email address. If a verification step requires you to submit personal data to prove you're not a robot, that is a strong red flag for phishing or fraud.
  • Be cautious with unexpected login requests, even if they originate from trusted domains or display valid SSL certificates.  
  • Verify the URL in the main browser’s window address bar – Browser-in-the-Browser attacks can spoof window chrome or pop-up but cannot change the actual domain shown by the browser itself.  
  • Keep browsers and security extensions up to date. 
  • Use trusted security solutions that inspect page scripts and dynamic assets, not just domain reputation. 

Kaspersky warns that popular cloud platforms have been used in over 390,000 phishing attacks

New Kaspersky research into phishing activity leveraging legitimate cloud platforms has revealed over 390,000 such attacks have been carried out in the last 12-months alone. These campaigns leverage trusted services such as Cloudflare Workers, Vercel, Netlify, GitHub Pages and IPFS to carry out sophisticated multi-stage attacks and even bypass multi-factor authentication. Detailed information is available in a new report on Securelist.
Kaspersky logo

About Kaspersky

Kaspersky is a global cybersecurity and digital privacy company founded in 1997. Innovating the industry with a Cyber Immunity approach, Kaspersky safeguards consumers, businesses, critical infrastructure, and governments from cyberthreats, with over a billion devices protected to date.

Kaspersky ensures Cybersecurity True to Business, focusing on providing clear outcomes, protecting revenue, easing workloads and preventing downtime. Kaspersky’s deep threat intelligence and security expertise is constantly transforming into innovative solutions and services for organizations of every size, from small businesses to large enterprises, combining proven AI-driven protection technologies with simple management and expert support.

Recognized in independent tests and trusted by millions of individuals worldwide and nearly 200,000 organizations, Kaspersky helps detect threats earlier, respond faster and operate with greater confidence and freedom, protecting what matters most to our clients. Learn more at www.kaspersky.com.

Related Articles Press Releases