Phishers are hijacking legitimate cloud infrastructure

Threat actors are increasingly using legitimate cloud platforms like Cloudflare Workers and GitHub Pages to host phishing infrastructure. This strategy allows attackers to evade detection by blending in with millions of legitimate websites hosted on the same services.
Why it matters
The abuse of trusted cloud infrastructure makes traditional domain-blocking security measures ineffective, necessitating more advanced content-based detection methods.
Threat actors are increasingly exploiting legitimate cloud services to evade detection and streamline the deployment of their scam infrastructure. Cloud hosting services and decentralized networks have become primary platforms for hosting phishing pages and sites. Throughout 2025 and 2026, we have observed phishing operators steadily migrate toward platforms like Cloudflare Workers, Vercel, Netlify, GitHub Pages, and IPFS. This post analyzes the mechanics of a real-life adversary-in-the-middle (AitM) attack in a cloud environment and presents detailed statistics on the platforms and domains phishers abuse most frequently.
Threat actors select platform-as-a-service (PaaS) offerings and distributed cloud environments to host phishing sites for much the same reasons legitimate software developers do:
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in