Phishers Use Trusted Cloud Infrastructure to Bypass MFA
Attackers are hosting transparent proxies on reputable cloud platforms to steal session cookies and evade security filters.
Cybercriminals are increasingly hijacking legitimate cloud infrastructure to host phishing operations, a strategy that allows them to bypass multi-factor authentication (MFA) and evade standard security detections. By operating from within trusted environments, threat actors deploy sophisticated attacks that appear as legitimate traffic to automated defense systems.
According to Securelist by Kaspersky, attackers are implementing multi-stage Adversary-in-the-Middle (AitM) attacks. This process involves using transparent proxies to harvest user credentials and session cookies in real-time. By capturing these session tokens, phishers bypass MFA, gaining unauthorized access to accounts without needing secondary verification codes. In one instance of infrastructure abuse, cybercriminals leveraged Google Cloud's 'Application Integration' service to blast out thousands of malicious emails, including a campaign in late 2025 and early 2026 that dispatched approximately 9,000 messages.
The Shift to Cloud-Native Deception
Traditional phishing relied on registering malicious domains, which security tools could easily flag and block based on poor reputation. However, as MFA adoption became widespread, attackers shifted toward AitM techniques. By hosting proxies on reputable platforms such as AWS, Azure, and Google Cloud, attackers benefit from the inherent trust and high reputation of these IP ranges. This makes it significantly harder for reputation-based filters to identify and block traffic before an attack succeeds.
This evolution mirrors a long-standing trend of exploiting trust. A historical report cited by Dark Reading noted that over 80% of phishing attacks once used hijacked legitimate websites, though that data dates back to 2009. Modern attackers have evolved this concept, moving from simple website hijacks to the strategic abuse of cloud-native services to maintain a 'safe haven' for their infrastructure.
Implications for Enterprise Security
This trend renders traditional domain-blocking and basic MFA insufficient for comprehensive protection. Because the underlying infrastructure is legitimate, security tools may not flag URLs as malicious until the attack is already well underway. This detection gap creates a critical window for attackers to exfiltrate data and compromise corporate networks.
The Path Toward Robust Authentication
The rise of cloud-hosted AitM attacks is forcing a shift in how organizations approach identity and access management. Security experts now advocate for more robust authentication methods, such as FIDO2 and WebAuthn, which are designed to be phishing-resistant. Additionally, there is a growing need for behavioral analysis—monitoring how a user interacts with a system—rather than relying solely on the reputation of the infrastructure from which a request originates.