HomeSecurityGoogle & Microsoft Abused to Target Corporate Users

Abuse of Google & Microsoft to target corporate users

Cybersecurity teams in businesses around the world are facing a new, highly sophisticated threat: phishing attacks that are now “hiding” within trusted cloud platforms (Google, Microsoft, etc.). This change marks a significant shift in the cybercrime landscape, as perpetrators abandon old methods and leverage the infrastructure of technology giants.

Google & Microsoft

From suspicious domains to legitimate cloud services

Traditionally, phishing attacks relied on newly registered domains, full of misspellings or strange endings, which often triggered security filters. But today, cybercriminals are opting for something much more effective: hosting their malicious infrastructure on legitimate services like Microsoft Azure Blob Storage, Google Firebase , and AWS CloudFront.

In this way, attacks acquire a "window of credibility", as the links come from domains that are considered safe and are used daily by millions of businesses.

Corporate users in the spotlight

One particularly concerning aspect is that these campaigns do not target simple personal email accounts. Instead, they focus on corporate users, in an attempt to compromise business systems and steal sensitive credentials.

See also: Increase in cyberattacks targeting identity

Access to corporate accounts can open the door to ransomware attacks, data leaks , or even financial fraud .

Multi-level avoidance techniques

Attacks usually start with highly convincing phishing emails containing links or QR codes. But their real advantage lies in the multiple layers of obfuscation techniques.

Many campaigns use CAPTCHA challenges and complex redirect chains, designed to bypass automated security scanners and static analysis systems. Analysts at Any.Run have identified this growing trend by monitoring phishing infrastructure in global security operations centers.

Abuse of Google & Microsoft to target corporate users

AiTM: When phishing bypasses MFA

The most dangerous attacks today are based on Adversary-in-the-Middle (AiTM) phishing kits . In these scenarios, attackers act as “invisible intermediaries” between the victim and the legitimate identification service.

See also: AI strengthens the attack chain in AWS environments

The result is terrifying: criminals can steal credentials and session tokens in real time, even if the user has multi-factor authentication (MFA) enabled.

The most common phishing kits

According to researchers, three tools dominate attacks against businesses:

  • Tycoon2FA
  • Sneaky2FA
  • EvilProxy

These platforms are distributed as phishing-as-a-service, making sophisticated attacks accessible even to less technical criminals. For example, Tycoon2FA campaigns have been linked to over 64,000 incidents, with organizations in the US and Europe being attacked multiple times a day.

Why traditional security indicators fail

The biggest problem for security teams is that classic detection indicators have lost their value. When a phishing page is hosted on Microsoft or Google infrastructure, the domains are considered inherently trustworthy.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

See also: OpenClaw flaw allows remote code execution

IP addresses, TLS fingerprints, and SSL certificates no longer offer clear signs of malicious activity, as they belong to legitimate cloud providers.

Abuse of Google & Microsoft to target corporate users

The Cloudflare and CDN challenge

Cloudflare's infrastructure adds even more complexity. As a CDN, it hides the actual origin server behind its own IP addresses, making it difficult to trace the malicious source.

Even if a domain is removed, attackers can register a new one within minutes, continuing their business seamlessly.

How can organisms defend themselves?

Experts emphasize that businesses now need more modern defense strategies. Continuous threat intelligence monitoring combined with behavioral analysis is essential.

At the same time, interactive solutions sandboxing allow analysts to safely explore attack chains and uncover credential theftthat static tools often miss.

The days of phishing relying on “rogue” domains are over. Today, attacks are leveraging the cloud itself, weaponizing trust in large platforms. For businesses, adapting to this new reality is not an option — it’s a necessity.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS