Cyber Security News

Threat Actors Abuse Microsoft & Google Platforms to Attack Enterprise Users

Enterprise security teams are facing a sophisticated new challenge as cybercriminals increasingly exploit trusted cloud platforms to launch phishing attacks.

Instead of relying on suspicious newly registered domains, threat actors now host their malicious infrastructure on legitimate services like Microsoft Azure Blob Storage, Google Firebase, and AWS CloudFront.

This strategic shift allows attackers to hide behind the reputation of trusted technology giants, making detection significantly more difficult for traditional security tools.

These campaigns specifically target corporate users rather than personal email accounts, representing a calculated effort to compromise business systems and steal sensitive enterprise credentials.

The attacks typically begin with convincing phishing emails containing links or QR codes that redirect victims through multiple layers of evasion techniques.

Many campaigns incorporate CAPTCHA challenges and complex redirect chains designed to bypass automated security scanners and static analysis systems.

Any.Run analysts identified this growing trend while monitoring phishing kit infrastructure across global security operations centers.

Their research revealed that the most dangerous campaigns employ Adversary-in-the-Middle (AiTM) phishing kits, which position attackers as invisible proxies between victims and legitimate authentication services.

This technique enables criminals to intercept credentials and session tokens in real-time, even when victims use multi-factor authentication protection.

Phishing attack (Source – Any.Run)

The three most prevalent phishing kits driving these enterprise-targeted attacks are Tycoon2FA, Sneaky2FA, and EvilProxy.

These sophisticated toolsets are distributed as Phishing-as-a-Service platforms, making advanced attack capabilities accessible to less technical criminals.

A malicious Tycoon2FA sample on a legitimate Microsoft Blob Storage domain (Source – Any.Run)

Security researchers discovered that Tycoon2FA campaigns alone have generated over 64,000 reported incidents, with US and European organizations encountering these attacks multiple times daily.

Detection Challenges and Security Implications

Traditional security indicators have become unreliable against these cloud-hosted threats.

When phishing pages reside on legitimate Microsoft or Google infrastructure, conventional detection methods fail because the hosting domains are inherently trusted.

POST request used by attackers to steal the password (Source – Any.Run)

IP addresses, TLS fingerprints, and SSL certificates no longer provide meaningful indicators of malicious activity, since they all belong to legitimate cloud service providers.

Cloudflare infrastructure presents particular challenges for security teams. The CDN service hides the actual origin server behind its own IP addresses, making it nearly impossible to identify or block the underlying malicious infrastructure.

‘Wrong password’ error message appears after password input (Source – Any.Run)

If defenders successfully take down one malicious domain, attackers simply register another and hide it behind Cloudflare within minutes, maintaining operational continuity without rebuilding their infrastructure.

Organizations should implement continuous threat intelligence monitoring combined with behavioral analysis capabilities to detect these advanced phishing campaigns.

Interactive sandboxing solutions enable security analysts to safely navigate through attack chains and observe malicious behavior in isolated environments, revealing the final credential theft pages that static security tools miss entirely.

Follow us on Google NewsLinkedIn, and X to Get More Instant UpdatesSet CSN as a Preferred Source in Google.

Tushar Subhra Dutta

Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.

Recent Posts

Google Chrome 153 Update Fixes 42 Security Flaws, Including 3 Critical Ones

Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the…

4 hours ago

CISA and NIST Release Technical Checklist for Safeguarding Identity Tokens From Theft and Misuse

The Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology…

14 hours ago

CISA Shares 17 Techniques Used by Hackers to Compromise Active Directory Environments

CISA and five international cybersecurity agencies have released detailed guidance describing 17 common techniques hackers…

15 hours ago

Apple Rolls Out Massive Security Update Fixing 273 Vulnerabilities Across Its Devices

Apple has released one of its largest coordinated security rollouts, addressing 273 distinct critical vulnerabilities…

15 hours ago

How to Keep Malware’s Rotating Infrastructure From Becoming a Detection Gap

You can’t detect today's attacks with yesterday’s threat intelligence; that’s how you could briefly formulate…

15 hours ago

Microsoft Bans Its AI Models From Launching Cyberattacks or Escalating Their Own Access

Microsoft has published a draft Humanist AI Code of Conduct that would prohibit its in-house…

16 hours ago