Abuse of Cloud-Native Infrastructure in Modern Phishing Campaigns
Essential information
- Published
- 08/05/2026 16:10
- Modified
- 11/05/2026 10:26
- Tags
- 2026-05-08 browser memory execution cloud-native phishing credential harvesting device code flow mfa bypass oauth token theft saas abuse trusted infrastructure abuse
- Related entities
- 1 observables, 14 techniques (mitre), 6 others
Description
An investigation has revealed a structural evolution in phishing operations where threat actors conduct entire campaigns through legitimate, enterprise-trusted cloud infrastructure rather than attacker-controlled systems. Adversaries weaponize platforms employees use daily, including cloud storage, productivity suites, and OAuth authentication endpoints. Attacks originate from legitimate Google or Microsoft systems, passing all authentication checks while linking to whitelisted cloud services. Multi-factor authentication is bypassed without touching passwords, and victim organizations show no anomalous SIEM events at compromise time. Campaigns employ five stages: delivery via provider-owned infrastructure, payload hosting on legitimate cloud storage, execution within browser memory using native APIs, credential theft through legitimate authentication flows, and persistent presence through licensed services. Detection requires behavioral analysis rather than traditional indicators, as attackers operate enti...