HomeSecurityHackers are abusing legitimate cloud platforms to "host" phishing kits

Hackers are abusing legitimate cloud platforms to “host” phishing kits

Phishing campaigns are evolving rapidly, with threat actors adopting increasingly insidious techniques. One of the most worrying trends recently is the misuse of legitimate cloud and content delivery platforms to host phishing kits , which significantly complicates the work of cybersecurity teams.

cloud phishing kits

From suspicious domains to trusted infrastructures

Traditionally, phishing attacks relied on newly registered domains with strange names or obvious signs of malicious use. This practice allowed security filters to detect and block the threats relatively easily. But today, hackers are changing strategy.

Instead of building new infrastructure, they leverage services from trusted providerssuch as Google, Microsoft Azure, and AWS CloudFront. Phishing pages are hosted on domains that are technically perfectly legal and safe, rendering classic domain-based filters almost useless.

See also: Phishing: Kimsuky hackers use malicious QR codes

Why is this method so effective?

The use of trusted cloud platforms allows attackers to “hide” behind the reputation of large technology companies. A URL ending in .windows.net or hosted on Google infrastructure is unlikely to arouse suspicion among users — or even automated security systems.

Additionally, many of these campaigns are designed specifically for corporate environments. Phishing kits automatically filter email addresses, ignoring free provider accounts and targeting exclusively corporate domains, where credentials are more valuable.

Hackers are abusing legitimate cloud platforms to "host" phishing kits

The case of the Tycoon phishing kit

Researchers at Any.Run discovered this pattern while analyzing several phishing kits. A notable example is the Tycoon, which operates via Microsoft Azure Blob Storage.

According to the analysis, Tycoon was hosted on the alencure[.]blob[.]core[.]windows[.]net domain, taking full advantage of Microsoft’s legitimate infrastructure. Most security vendors classify such cloud domains as safe — and rightly so, as the infrastructure itself is not malicious. The problem lies in the content delivered through it.

See also: Phishing emails mimic DocuSign to distribute malware

When reputation is not enough for security

This phenomenon reveals a critical gap in modern defense strategies. Evaluating a URL based on domain reputation alone is no longer sufficient. Attackers don't need to "contaminate" the infrastructure; they just need to exploit it.

Thus, even organizations with strong email filters and web protection can fall victim if they do not have mechanisms that examine the behavior of a page and not just its origin.

The need for behavior analysis

Experts agree that addressing these threats requires a shift from simple domain checks to dynamic behavioral analysis. Security platforms must monitor in real time how users interact with pages hosted in the cloud.

Hackers are abusing legitimate cloud platforms to "host" phishing kits

Indications such as credential entry forms, redirects after login, or suspicious JavaScript patterns can reveal malicious activity, even if the page is hosted in a completely trusted environment.

See also: Microsoft: Incorrect email routing enables internal domain phishing

Selecting the team

🔑 Secure your passwords with Proton Pass

Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.

  • ✔ Encrypted storage of passwords & passkeys
  • ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
  • ✔ Free version — on all devices
Get your free Proton Pass →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Detection and response speed

Any.Run Sandbox, according to the researchers, can uncover such threats in less than 60 seconds, drastically reducing both average detection time and response time. This speed is critical, especially in targeted attacks that spread quickly via email or collaborative messaging.

What should organizations do?

Businesses are urged to adopt more proactive threat hunting, focusing on patterns of abuse of platforms such as Microsoft Azure Blob Storage, Firebase Cloud Storage, and Google Sites.

Relevant breach indicators that have been linked to such campaigns include domains such as mphdvh[.]icu, kamitore[.]com, aircosspascual[.]com , and Lustefea[.]my[.]id.

The message is clear: as hackers exploit the reliability of the cloud, security must become smarter, more adaptive, and less dependent on outdated detection methods.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS