Hackers Abusing Legitimate Cloud and CDN Platforms to Host Phishing Kits
## Cybersecurity: Cloud-Hosted Phishing Kits
Cybersecurity: Cloud-Hosted Phishing Kits
Threat actors are increasingly leveraging trusted cloud and content delivery network platforms to host phishing kits, posing significant detection challenges for security teams.
Unlike traditional phishing campaigns that utilize newly registered, suspicious domains, these attacks exploit legitimate infrastructure from providers such as Google, Microsoft Azure, and AWS CloudFront. This method allows attackers to bypass many security filters as the domains initially appear trustworthy.
The migration towards cloud-based phishing infrastructure signifies a notable evolution in social engineering attacks. Victims often encounter familiar domain names from recognized technology companies, increasing the likelihood of entering sensitive credentials.
Network monitoring tools face challenges in flagging these activities, as they see ordinary HTML content loading from established cloud services rather than suspicious traffic patterns.
Any.Run researchers identified the Tycoon phishing kit operating from Microsoft Azure Blob Storage, using the domain alencure[.]blob[.]core[.]windows[.]net. The Sneaky2FA phishing kit was found on Firebase Cloud Storage and AWS CloudFront, employing fake Microsoft 365 login pages to collect corporate credentials. The EvilProxy phishing kit uses Google Sites at sites[.]google[.]com to host its malicious pages.
Threat actors are increasingly leveraging trusted cloud and content delivery network platforms to host phishing kits, posing significant detection challenges for security teams.
Security teams encounter unique challenges when addressing cloud-hosted phishing infrastructure. Traditional domain reputation checks often fail because the hosting platforms are legitimate services used by numerous organizations for valid purposes.
Security vendors classify these cloud domains as safe, which is technically accurate. The malicious activity resides in the content served, not the infrastructure itself.
The solution necessitates behavioral analysis rather than simple domain checks. Security platforms must analyze user interactions with these cloud-hosted pages and identify suspicious patterns in real-time. Any.Run Sandbox demonstrates this capability by exposing threats in under 60 seconds, reducing both mean time to detect and mean time to respond.
Organizations should implement threat intelligence lookups that specifically search for abuse patterns on Microsoft Azure Blob Storage, Firebase Cloud Storage, and Google Sites platforms.
Related indicators of compromise include mphdvh[.]icu, kamitore[.]com, aircosspascual[.]com, and Lustefea[.]my[.]id.
Based on reporting by Cyber Security News.



