Last month, Cloudflare announced a new service that will provide an IPFS gateway, allowing users to access the IPFS network through their browser. Thus, all connections made use the SSL certificate provided by Cloudflare.

Using Cloudflare's IPFS gateway, hackers can direct their victims to html files they host on the IPFS network and confuse them by making the link appear secure. In the image below you can see a malicious phishing that uses exactly this technology.

The only strange thing the user might notice on this page is the URL, which shows that it is a file from the IPFS network. When the user fills in the blanks, their details are recorded in a database maintained by the hacker, and will likely be used later.
This hacker has been involved in several phishing attacks since July 2018. Using VirusTotal ,we can see many URLs that are related to the site that the hacker's database maintains. After checking, we found that while some of the pages are no longer available, there are many that are still available.
Even just from the URL you can tell that this is not a genuine and secure website; many may not notice it in their haste and may enter their details. The green indicator shows that the page uses the SSL protocol, and for many that is enough to trust its source.
