安全研究人员发现,威胁行为者正在大规模利用合法云服务平台部署网络钓鱼基础设施[1]。在2025年8月至2026年7月期间,安全团队共阻止了224,984个用于钓鱼攻击的独特第三级域名,并破获超过390,000个托管在云平台和IPFS网络上的钓鱼页面[1]。其中,Cloudflare和Vercel成为最常被滥用的云平台,GitHub Pages排名第三[1]。
攻击者采用复杂的中间人(AitM)攻击机制结合浏览器内浏览器(BitB)技术实施攻击[1]。攻击分为三个阶段展开:首先收集目标邮件地址,其次初始化透明代理,最后进行会话劫持和浏览器窗口欺骗[1]。具体而言,攻击者利用服务工作者(Service Worker)部署Ultraviolet网络代理库以拦截所有网络请求,BitB攻击则渲染虚假浏览器窗口显示受信任的URL,同时AitM代理在后台拦截受害者的凭证和会话令牌[1]。
Threat actors have been systematically exploiting legitimate cloud services to launch large-scale phishing campaigns, according to security research. Between August 2025 and July 2026, security teams blocked 224,984 unique third-level domains used in phishing attacks and identified over 390,000 phishing pages hosted on cloud platforms and IPFS networks [1]. The most frequently abused platforms include Cloudflare and Vercel, with GitHub Pages ranking as the third most exploited service [1].
The attacks operate through a sophisticated three-stage mechanism that combines man-in-the-middle (AitM) tactics with browser-in-browser (BitB) technology [1]. The campaign begins with email address collection, followed by transparent proxy initialization, and culminates in session hijacking paired with fraudulent browser window displays [1]. Attackers deploy service workers to launch the Ultraviolet web proxy library, which intercepts all network requests, while the BitB component renders fake browser windows displaying trusted URLs to deceive users [1]. This layered approach enables attackers to simultaneously intercept credentials and session tokens in the background, effectively compromising multi-factor authentication sessions [1].