HomeSecurityPhishing campaign targeted Google Cloud and Cloudflare for 3 years

Phishing campaign targeted Google Cloud and Cloudflare for 3 years

A sophisticated phishing operation has been operating covertly for over three years on Google Cloud and Cloudflare, impersonating major companies, including defense contractor Lockheed Martin.

The phishing campaign used advanced obfuscation techniques and compromised expired domains, showing a worrying failure in detection capabilities from two of the largest internet service providers.

See also: Phishing campaign targets hoteliers through malicious ads

Phishing

The operation began with attackers acquiring expired domains previously owned by legitimate organizations, then developing cloned websites of Fortune 500. The scheme specifically targeted high-value domains with established reputations and active social media, making the impersonations more convincing to unsuspecting users. One notable example included the domain militaryfighterjet.com, which originally hosted content about military aircraft but was transformed into a gaming site that also served as a perfect clone of Lockheed Martin’s corporate website.

The attackers used advanced cloaking technology that presented different content depending on the user and their geographic location. When opened by search engine crawlers or through Google search results, users saw cloned websites that appeared legitimate. However, direct access via a browser revealed gambling content, creating a dual-purpose infrastructure that evaded automated detection systems while serving illegal content to real users.

Deep Specter Research analysts identified this massive operation through their investigation into the militaryfighterjet.com domain conversion. Their analysis revealed that the infrastructure consisted of over 48,000 active virtual machines organized into 86 distinct clusters, with the majority hosted on Google Cloud platforms in Hong Kong and Taiwan. The researchers discovered evidence of the operation dating back to 2021, with significant periods of expansion coinciding with major cybersecurity incidents and data breaches worldwide.

See also: 'Sindoor Dropper': New malware campaign targets Linux

Phishing campaign targeted Google Cloud and Cloudflare for 3 years

The technical sophistication of the phishing campaign becomes apparent when we examine the underlying infrastructure and deployment methods. Analysts at Deep Specter Research noted that the attackers used HTTrack Website Copier, a legitimate web scraping tool, to create exact clones of the targeted organizations’ websites. Evidence of this tool’s use was found embedded in the HTML comments of the cloned websites, including timestamps indicating when specific web pages were copied.

Analysis of the company’s source code revealed strategic implementation details that made detection particularly difficult. The cloaking system examined HTTP headers, user strings, and IP geolocation data to determine whether visitors were legitimate users, search engine crawlers, or security researchers. This selective content delivery allowed the malicious websites to maintain high search engine rankings while serving up gambling content and potential malware to targeted demographics.

The infrastructure demonstrated remarkable resilience and scalability, with the attackers maintaining over 200 cloned tokens across multiple sectors, including military, healthcare, and construction. The largest single cluster contained nearly 6,000 virtual machines serving cloned content from a single organization, suggesting that this may represent preparation for a large-scale breach campaign.

See also: Largest GreedyBear attack ever steals $1 million

Phishing campaign targeted Google Cloud and Cloudflare for 3 years
Phishing campaign targeted Google Cloud and Cloudflare for 3 years

Analysis of the network architecture revealed eight senior administrators coordinating 78 regular cluster administrators, indicating a hierarchical command structure typical of professional cybercrime operations. The attackers strategically exploited the solvency of Google Cloud and Cloudflare infrastructure to bypass security filters.

Selecting the team

🔑 Secure your passwords with Proton Pass

Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.

  • ✔ Encrypted storage of passwords & passkeys
  • ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
  • ✔ Free version — on all devices
Get your free Proton Pass →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS