Phishing with Cloudflare Workers: Transparent Phishing and HTML Smuggling
Cosa significa
MISP EudorIA ha pubblicato l'advisory "Phishing with Cloudflare Workers: Transparent Phishing and HTML Smuggling". Occorre verificarne l'applicabilita rispetto a prodotti e servizi in uso.
Perché conta
Un advisory attendibile puo richiedere verifiche, aggiornamenti o mitigazioni, ma l'applicabilita va confermata sul perimetro reale.
Azioni consigliate
- Verificare tecnologie, versioni e servizi interessati nel proprio inventario.
- Consultare la fonte originale prima di pianificare la mitigazione.
Testo acquisito dalla fonte
Evento MISP pubblicato con TLP:CLEAR: Phishing with Cloudflare Workers: Transparent Phishing and HTML Smuggling. Report from - [URL rimossa] (1717011547) Phishing with Cloudflare Workers: Transparent Phishing and HTML Smuggling ========================================================================= May 23 2024 By [Jan Michael Alcantara]([URL rimossa]) Summary ------- Netskope Threat Labs is tracking multiple phishing campaigns that abuse Cloudflare Workers. The campaigns are likely the work of different attackers since they use two very different techniques. One campaign (similar to the [previously disclosed]([URL rimossa]) Azorult campaign) uses HTML smuggling, a detection evasion technique often used for downloading malware, to hide the phishing content from network inspection. The other uses a method called transparent phishing, where the attacker uses Cloudflare Workers to act as a reverse proxy server for a legitimate login page, intercepting traffic between the victim and the login page to capture credentials, cookies, and tokens. Netskope Threat Labs has been tracking an increasing number of Netskope users targeted by malicious content hosted in Cloudflare Workers throughout 2023 and into 2024. The number of targeted users appears to have leveled off so far in 2024, although the number of domains continues to increase. At the same time, the distinct number of applications hosting the malicious content continues to increase, indicating that attackers are constantly creating new ap
- Fonte
- MISP EudorIA
- Entità pubblicatrice
- MISP EudorIA
- Tipo entità
- Comunità di intelligence
- Area
- Global
- Lingua originale
- it · traduzione non necessaria
- Pubblicazione
- 30/07/2026 02:51
- Condivisione
- TLP:CLEAR
- Indicatori dichiarati dalla fonte
- 4183
- IOC indicizzati per la ricerca
- 0 valori nel periodo di conservazione
- IOC disponibili nel feed STIX
- 0Nessun export attualmente autorizzato per questa scheda.
- Evento MISP
- f65efb02-c563-44a7-9036-516219a24243
- MITRE ATT&CK
- HTML Smuggling - T1027.006, Phishing - T1566
- Classificazione
- Bassa