{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/ipfs/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Cloudflare Workers","Vercel","Netlify","GitHub Pages","IPFS"],"_cs_severities":["high"],"_cs_tags":["phishing","aitm","cloud","credential-harvesting"],"_cs_type":"advisory","_cs_vendors":["Cloudflare","Vercel","Netlify","GitHub","Microsoft"],"content_html":"\u003cp\u003eThreat actors are migrating phishing infrastructure to legitimate cloud platforms such as Cloudflare Workers, Vercel, Netlify, GitHub Pages, and IPFS. This strategy exploits the inherent trust associated with reputable CDN and cloud domains, allowing attackers to evade IP-based blocking and security filtering. By leveraging free-tier developer accounts that do not require identity verification, operators can scale malicious infrastructure rapidly.\u003c/p\u003e\n\u003cp\u003eThe core of these campaigns is a sophisticated Adversary-in-the-Middle (AitM) approach that uses browser-side service workers to intercept network requests. By utilizing the legitimate Ultraviolet proxy library, the phishing pages dynamically rewrite traffic in real-time, effectively bypassing traditional proxy-based security controls. This approach allows attackers to harvest login credentials and MFA tokens while the victim interacts with what appears to be a legitimate, HTTPS-secured website. The use of URL hash fragments to pass sensitive data between attack stages ensures that malicious parameters remain hidden from standard network-based detection systems.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttackers deliver a phishing email containing a link to a compromised legitimate website.\u003c/li\u003e\n\u003cli\u003eThe compromised website acts as a disposable relay to capture the victim's email address via a fake CAPTCHA.\u003c/li\u003e\n\u003cli\u003eThe victim is redirected to a cloud-hosted subdomain (e.g., workers.dev) with the email address embedded in the URL hash.\u003c/li\u003e\n\u003cli\u003eThe phishing page presents a genuine CAPTCHA challenge to confirm the victim is not a bot.\u003c/li\u003e\n\u003cli\u003eUpon success, a malicious service worker is registered in the browser to intercept all outgoing network requests.\u003c/li\u003e\n\u003cli\u003eThe service worker injects the Ultraviolet library to create a transparent proxy that rewrites login forms.\u003c/li\u003e\n\u003cli\u003eThe user enters credentials and MFA tokens, which are captured and proxied by the attacker's infrastructure.\u003c/li\u003e\n\u003cli\u003eThe attacker uses the captured credentials and session tokens to gain unauthorized access to the target's account.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful attacks result in full credential and MFA token compromise, leading to account takeover. Because these campaigns reside on reputable cloud subdomains, they successfully bypass many traditional reputation-based security filters. The infrastructure allows attackers to bypass MFA mechanisms by capturing session cookies, significantly increasing the risk to enterprise authentication environments.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImplement content-based analysis for web traffic to identify malicious JavaScript (e.g., unauthorized service worker registration) rather than relying solely on domain reputation.\u003c/li\u003e\n\u003cli\u003eMonitor browser activity for the suspicious registration of service workers on domains that are not part of the organization's sanctioned enterprise application suite.\u003c/li\u003e\n\u003cli\u003eDeploy FIDO2/WebAuthn-based phishing-resistant MFA, which inherently mitigates AitM credential harvesting attacks.\u003c/li\u003e\n\u003cli\u003eEducate users on the risks of interacting with links that redirect through reputable cloud platforms (like workers.dev) when prompted for sensitive corporate credentials.\u003c/li\u003e\n\u003cli\u003eReview proxy logs for traffic patterns associated with known browser-based proxy libraries like Ultraviolet.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-04T13:40:05Z","date_published":"2026-08-04T13:40:05Z","id":"https://feed.craftedsignal.io/briefs/2026-08-cloud-aitm-phishing/","summary":"Threat actors are increasingly abusing reputable PaaS providers to host multi-stage AitM phishing campaigns that use browser service workers and the Ultraviolet library to intercept credentials and MFA tokens.","title":"Adversary-in-the-Middle Phishing via Legitimate Cloud Platforms","url":"https://feed.craftedsignal.io/briefs/2026-08-cloud-aitm-phishing/"}],"language":"en","title":"CraftedSignal Threat Feed - IPFS","version":"https://jsonfeed.org/version/1.1"}