Abuse of Cloud-Native Infrastructure in Modern Phishing Campaigns
May 11, 2026, 10:26 a.m.
Description
An investigation has revealed a structural evolution in phishing operations where threat actors conduct entire campaigns through legitimate, enterprise-trusted cloud infrastructure rather than attacker-controlled systems. Adversaries weaponize platforms employees use daily, including cloud storage, productivity suites, and OAuth authentication endpoints. Attacks originate from legitimate Google or Microsoft systems, passing all authentication checks while linking to whitelisted cloud services. Multi-factor authentication is bypassed without touching passwords, and victim organizations show no anomalous SIEM events at compromise time. Campaigns employ five stages: delivery via provider-owned infrastructure, payload hosting on legitimate cloud storage, execution within browser memory using native APIs, credential theft through legitimate authentication flows, and persistent presence through licensed services. Detection requires behavioral analysis rather than traditional indicators, as attackers operate enti...
Tags
Date
- Created: May 8, 2026, 4:10 p.m.
- Published: May 8, 2026, 4:10 p.m.
- Modified: May 11, 2026, 10:26 a.m.
Additional Informations
- Finance
- Manufacturing
- Transport
- Telecommunications
- Technology
- Government