Threat actors are systematically abusing legitimate cloud PaaS platforms and IPFS gateways to host multi-stage adversary-in-the-middle (AitM) phishing infrastructure that bypasses MFA. The attack chain uses compromised websites as disposable relays, Cloudflare Workers for core phishing content, browser service workers with the Ultraviolet proxy library to intercept all tab network traffic, and Browser-in-the-Browser (BitB) spoofing to display trusted URLs while silently capturing credentials and session tokens. Over 390,000 phishing pages on legitimate cloud platforms were identified in 12 months, with reputation-based blocklists proving ineffective against programmatically generated subdomains on trusted apex domains.
Service Worker
1 post
How legitimate cloud platforms enable phishers to bypass MFA