Phishing with Cloudflare Workers: Transparent Phishing and HTML Smuggling
What it means
MISP EudorIA ha pubblicato l'advisory "Phishing with Cloudflare Workers: Transparent Phishing and HTML Smuggling". Occorre verificarne l'applicabilita rispetto a prodotti e servizi in uso.
Why it matters
Un advisory attendibile puo richiedere verifiche, aggiornamenti o mitigazioni, ma l'applicabilita va confermata sul perimetro reale.
Recommended actions
- Verificare tecnologie, versioni e servizi interessati nel proprio inventario.
- Consultare la fonte originale prima di pianificare la mitigazione.
Text acquired from the source
Evento MISP pubblicato con TLP:CLEAR: Phishing with Cloudflare Workers: Transparent Phishing and HTML Smuggling. Report from - [URL rimossa] (1717011547) Phishing with Cloudflare Workers: Transparent Phishing and HTML Smuggling ========================================================================= May 23 2024 By [Jan Michael Alcantara]([URL rimossa]) Summary ------- Netskope Threat Labs is tracking multiple phishing campaigns that abuse Cloudflare Workers. The campaigns are likely the work of different attackers since they use two very different techniques. One campaign (similar to the [previously disclosed]([URL rimossa]) Azorult campaign) uses HTML smuggling, a detection evasion technique often used for downloading malware, to hide the phishing content from network inspection. The other uses a method called transparent phishing, where the attacker uses Cloudflare Workers to act as a reverse proxy server for a legitimate login page, intercepting traffic between the victim and the login page to capture credentials, cookies, and tokens. Netskope Threat Labs has been tracking an increasing number of Netskope users targeted by malicious content hosted in Cloudflare Workers throughout 2023 and into 2024. The number of targeted users appears to have leveled off so far in 2024, although the number of domains continues to increase. At the same time, the distinct number of applications hosting the malicious content continues to increase, indicating that attackers are constantly creating new ap
- Source
- MISP EudorIA
- Publishing entity
- MISP EudorIA
- Entity type
- Intelligence community
- Area
- Global
- Original language
- it ยท translation not needed
- Publication
- 30/07/2026 02:51
- Sharing
- TLP:CLEAR
- Indicators reported by the source
- 4183
- IOCs indexed for lookup
- 0 values within the retention period
- IOCs available in the STIX feed
- 0No export currently authorised for this record.
- MISP event
- f65efb02-c563-44a7-9036-516219a24243
- MITRE ATT&CK
- HTML Smuggling - T1027.006, Phishing - T1566
- Classification
- Low