EudorIACyber Intelligence
Operational monitoring Newsletter IT EN
← Back to intelligence
Technical advisory

Phishing with Cloudflare Workers: Transparent Phishing and HTML Smuggling

Verified open source
Intelligence with traceable provenance. EudorIA retains technical indicators acquired from supported feeds, with source, date and context. Shareable IOCs are available in the STIX feeds; detection and blocking actions require an assessment of validity, confidence and applicability to the customer's environment. Browse STIX feeds
EudorIA operational summary

What it means

Priority 55/100

MISP EudorIA ha pubblicato l'advisory "Phishing with Cloudflare Workers: Transparent Phishing and HTML Smuggling". Occorre verificarne l'applicabilita rispetto a prodotti e servizi in uso.

Why it matters

Un advisory attendibile puo richiedere verifiche, aggiornamenti o mitigazioni, ma l'applicabilita va confermata sul perimetro reale.

AudienceITSOCCISO

Text acquired from the source

Evento MISP pubblicato con TLP:CLEAR: Phishing with Cloudflare Workers: Transparent Phishing and HTML Smuggling. Report from - [URL rimossa] (1717011547) Phishing with Cloudflare Workers: Transparent Phishing and HTML Smuggling ========================================================================= May 23 2024 By [Jan Michael Alcantara]([URL rimossa]) Summary ------- Netskope Threat Labs is tracking multiple phishing campaigns that abuse Cloudflare Workers. The campaigns are likely the work of different attackers since they use two very different techniques. One campaign (similar to the [previously disclosed]([URL rimossa]) Azorult campaign) uses HTML smuggling, a detection evasion technique often used for downloading malware, to hide the phishing content from network inspection. The other uses a method called transparent phishing, where the attacker uses Cloudflare Workers to act as a reverse proxy server for a legitimate login page, intercepting traffic between the victim and the login page to capture credentials, cookies, and tokens. Netskope Threat Labs has been tracking an increasing number of Netskope users targeted by malicious content hosted in Cloudflare Workers throughout 2023 and into 2024. The number of targeted users appears to have leveled off so far in 2024, although the number of domains continues to increase. At the same time, the distinct number of applications hosting the malicious content continues to increase, indicating that attackers are constantly creating new ap

Source
MISP EudorIA
Publishing entity
MISP EudorIA
Entity type
Intelligence community
Area
Global
Original language
it ยท translation not needed
Publication
30/07/2026 02:51
Sharing
TLP:CLEAR
Indicators reported by the source
4183
IOCs indexed for lookup
0 values within the retention period
IOCs available in the STIX feed
0No export currently authorised for this record.
MISP event
f65efb02-c563-44a7-9036-516219a24243
MITRE ATT&CK
HTML Smuggling - T1027.006, Phishing - T1566
Classification
Low
Open the original source