Saturday, August 15, 2026
LIVE
Ugandan villages still contest land titles as oil development advances///Nigerian Troops Repel Bandit Attack on Kebbi Workers///NLC Queries Lagos Chairman Over Ties to Pro-Tinubu Group///Côte d’Ivoire Names New Leader for Blé Goudé’s COJEP Party///United States Highlights Civilian Deaths in Nigeria Terror Fight///Zimbabwe Pledges New Ferry and Road Repair After Lake Kariba Disaster///Ebola death toll reaches two thousand in Democratic Republic of the Congo///Forced Conscription Reports Emerge Across Ethiopia Oromia Region///Ebola outbreak reaches displacement camps in eastern Democratic Republic of the Congo///Hacking Group Claims Data Theft from Shell and Other Global Firms///Turkey warns of radical measures if Israel rejects Gaza peace deal terms///Nigerian President Urged to Engage Niger Delta Leader for Reelection Campaign///Ugandan villages still contest land titles as oil development advances///Nigerian Troops Repel Bandit Attack on Kebbi Workers///NLC Queries Lagos Chairman Over Ties to Pro-Tinubu Group///Côte d’Ivoire Names New Leader for Blé Goudé’s COJEP Party///United States Highlights Civilian Deaths in Nigeria Terror Fight///Zimbabwe Pledges New Ferry and Road Repair After Lake Kariba Disaster///Ebola death toll reaches two thousand in Democratic Republic of the Congo///Forced Conscription Reports Emerge Across Ethiopia Oromia Region///Ebola outbreak reaches displacement camps in eastern Democratic Republic of the Congo///Hacking Group Claims Data Theft from Shell and Other Global Firms///Turkey warns of radical measures if Israel rejects Gaza peace deal terms///Nigerian President Urged to Engage Niger Delta Leader for Reelection Campaign///
Subscribe
Africa
Independent · Digital
The African Herald
PoliticsAI-assisted

Hackers Abusing Legitimate Cloud and CDN Platforms to Host Phishing Kits

## Cybersecurity: Cloud-Hosted Phishing Kits

Cybersecurity: Cloud-Hosted Phishing Kits

Threat actors are increasingly leveraging trusted cloud and content delivery network platforms to host phishing kits, posing significant detection challenges for security teams.

Unlike traditional phishing campaigns that utilize newly registered, suspicious domains, these attacks exploit legitimate infrastructure from providers such as Google, Microsoft Azure, and AWS CloudFront. This method allows attackers to bypass many security filters as the domains initially appear trustworthy.

The migration towards cloud-based phishing infrastructure signifies a notable evolution in social engineering attacks. Victims often encounter familiar domain names from recognized technology companies, increasing the likelihood of entering sensitive credentials.

Network monitoring tools face challenges in flagging these activities, as they see ordinary HTML content loading from established cloud services rather than suspicious traffic patterns.

Any.Run researchers identified the Tycoon phishing kit operating from Microsoft Azure Blob Storage, using the domain alencure[.]blob[.]core[.]windows[.]net. The Sneaky2FA phishing kit was found on Firebase Cloud Storage and AWS CloudFront, employing fake Microsoft 365 login pages to collect corporate credentials. The EvilProxy phishing kit uses Google Sites at sites[.]google[.]com to host its malicious pages.

Threat actors are increasingly leveraging trusted cloud and content delivery network platforms to host phishing kits, posing significant detection challenges for security teams.
Thandiwe Moyo · The African Herald

Security teams encounter unique challenges when addressing cloud-hosted phishing infrastructure. Traditional domain reputation checks often fail because the hosting platforms are legitimate services used by numerous organizations for valid purposes.

Security vendors classify these cloud domains as safe, which is technically accurate. The malicious activity resides in the content served, not the infrastructure itself.

The solution necessitates behavioral analysis rather than simple domain checks. Security platforms must analyze user interactions with these cloud-hosted pages and identify suspicious patterns in real-time. Any.Run Sandbox demonstrates this capability by exposing threats in under 60 seconds, reducing both mean time to detect and mean time to respond.

Advertisement

Organizations should implement threat intelligence lookups that specifically search for abuse patterns on Microsoft Azure Blob Storage, Firebase Cloud Storage, and Google Sites platforms.

Related indicators of compromise include mphdvh[.]icu, kamitore[.]com, aircosspascual[.]com, and Lustefea[.]my[.]id.

Based on reporting by Cyber Security News.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories