Phishers hijack legitimate cloud platforms to bypass MFA

Phishers are hijacking legitimate cloud infrastructure

Phishers hijack legitimate cloud platforms to bypass MFA

A new report reveals how attackers abuse Cloudflare Workers, Vercel, and other trusted cloud services to host multi-stage adversary-in-the-middle (AitM) phishing attacks that bypass multi-factor authentication. The analysis details a real-world attack using a fake CAPTCHA, a service worker proxy, and a browser-in-the-browser trick to steal Microsoft credentials and session tokens. Over 390,000 phishing pages were blocked on these platforms in 12 months, with pages.dev, vercel.app, and github.io among the most abused domains.

Combining BitB with AitM significantly increases the threat: BitB provides a convincing, trusted visual wrapper (displaying a legitimate URL and branding), while the hidden AitM proxy quietly handles traffic interception and session hijacking behind the scenes.

More from this day

2026-08-05