THE article examines how threat actors exploit legitimate cloud platforms for phishing attacks, particularly through tactics that utilize the trust associated with these services. It discusses the advantages for phishers, including swift account creation, anonymity, and the challenge of blocking domains without affecting legitimate users. A detailed multi-stage adversary-in-the-middle (AitM) phishing attack is outlined, involving steps like contact harvesting, initializing proxies, and session hijacking.
Statistics from a 12-month analysis reveal significant use of platforms like Cloudflare, Vercel, and GitHub Pages for phishing. Recommendations for defense include caution with requests from reputable domains, scrutinizing CAPTCHA systems, and using enhanced email security solutions.