How legitimate cloud platforms enable phishers to bypass MFA
Kaspersky researchers document a sophisticated multi-stage adversary-in-the-middle (AitM) phishing campaign that exploits legitimate cloud platforms (Cloudflare Workers, Vercel, GitHub Pages, Netlify) to bypass MFA and hijack user sessions. The attack chains a fake CAPTCHA landing page, service worker-based transparent proxy (using Ultraviolet), and browser-in-browser (BitB) UI spoofing to intercept credentials and session tokens. Telemetry from August 2025–July 2026 shows 224,984 unique phishing domains across cloud platforms, with Cloudflare Pages (24.9%), Vercel (13.8%), and GitHub Pages (13.7%) dominating the abuse landscape.