developer domains "pages.dev" and "workers.dev," used for developing websites and facilitating serverless computing, are increasingly being abused by cybercriminals for phishing and other malicious activities.
See also: Cloudflare: Lost 55% of logs for 3.5 hours

According to cybersecurity firm Fortra, abuse of these domains has increased between 100% and 250% compared to 2023.
Researchers believe that the use of these developer domains aims to improve the legitimacy and effectiveness of these malicious campaignsby taking advantage of Cloudflare's trusted brand, service reliability, low cost of use, and reverse proxy options that complicate detection.
Cloudflare Pages is a platform designed for developers to create, develop, and host fast, scalable websites directly on Cloudflare's global content delivery network (CDN).
See also: Cloudflare blocked the largest DDoS attack ever recorded (3.8 Tbps)
It features static website hosting, supports a range of modern web application development frameworks, and offers SSL/TLS encryption by default, securing HTTPS connections without requiring additional configuration.

Fortra reports that Cloudflare's developer domains have become a tool for cybercriminals who abuse it by hosting intermediary phishing that redirect victims to malicious websites, such as fake Microsoft Office365.
Victims are led there via links embedded in fraudulent PDF files or phishing email bodies, which go undetected by security products thanks to Cloudflare's reputation.
Fortra also notes that threat actors are using the “bccfoldering” tactic to hide the scale of their email distribution campaigns.
See also: Cloudflare: Warns of hacking gang targeting Asia
In today’s cyberspace, malicious actors are a significant threat to the security and privacy of our data. Threat actors can be individuals, groups, or organized entities that seek to cause harm, compromise system security, or steal sensitive information. Malicious actors can be hackers, cyberattacks, or insider threats, such as unwanted personal or professional individuals. Understanding and addressing malicious actors is essential to protecting them and maintaining the security of our systems.
Source: bleepingcomputer
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
