Hacker News·4 min read·medium

Phishers are hijacking legitimate cloud infrastructure

L
lschueller
Phishers are hijacking legitimate cloud infrastructure
AI Summary

Threat actors are increasingly using legitimate cloud platforms like Cloudflare Workers and GitHub Pages to host phishing infrastructure. This strategy allows attackers to evade detection by blending in with millions of legitimate websites hosted on the same services.

Threat actors are increasingly exploiting legitimate cloud services to evade detection and streamline the deployment of their scam infrastructure. Cloud hosting services and decentralized networks have become primary platforms for hosting phishing pages and sites. Throughout 2025 and 2026, we have observed phishing operators steadily migrate toward platforms like Cloudflare Workers, Vercel, Netlify, GitHub Pages, and IPFS. This post analyzes the mechanics of a real-life adversary-in-the-middle (AitM) attack in a cloud environment and presents detailed statistics on the platforms and domains phishers abuse most frequently.

Continue reading on Headlinne

Create a free account to read the full article.

Read full article →
technologybusiness

Get the full story

Sign up for Headlinne to unlock AI insights, political bias analysis, and your personalized news feed.

Create free account

Already have an account? Sign in