CyberSecurityNews

Attackers Abuse Trusted Cloud Services to Hide Phishing Attacks Against Financial Organizations


Cybercriminals are increasingly weaponizing trusted cloud platforms such as Microsoft Azure, Google Firebase, Google Cloud Storage, Amazon Web Services, and Cloudflare to host phishing infrastructure aimed squarely at the financial sector, making malicious traffic nearly indistinguishable from legitimate business activity.

Security researchers describe this as a structural shift toward what some call Trusted Infrastructure Phishing, where every stage of an attack, from delivery to credential theft, runs through legitimate, enterprise-approved services rather than attacker-owned domains.

Trusted Cloud Services Abused for Phishing

Financial institutions rely heavily on cloud storage, document-sharing tools, and vendor platforms for daily operations, which gives attackers a ready-made attack surface with built-in credibility.

Recent campaigns have exploited Google Cloud Application Integration’s legitimate “Send Email” feature to dispatch phishing messages directly from google.com addresses, allowing them to pass SPF, DKIM, and DMARC checks that would normally flag spoofed senders.

Victims who click through are routed via Google Cloud Storage links and CAPTCHA gates before landing on fake Microsoft 365 login pages hosted on AWS S3, a multi-stage redirect chain designed to defeat both automated scanners and human suspicion.

Similar tactics have surfaced across Microsoft 365 tenants, where attackers manipulate tenant display names and route phishing lures through Microsoft’s own infrastructure, again passing standard authentication checks.

Fake Microsoft Authentication Page (Image Source: ANY. RUN)

This abuse extends well beyond email delivery. Threat actors are increasingly embedding adversary-in-the-middle phishing kits inside legitimate content delivery networks and cloud subdomains, capturing both credentials and live authentication tokens to bypass multifactor authentication entirely.

Because these kits operate as a proxy sitting between the victim and the real service, session hijacking becomes far harder to detect than a simple stolen password, a problem that is especially acute for banks and financial firms where a single compromised session can expose sensitive transaction data.

Traditional email gateways and domain reputation tools offer little protection here because the infrastructure itself is legitimate. Detection instead has to shift toward post-delivery behavioral signals: click telemetry, redirect-chain analysis, and anomalous authentication events after a link has already been opened.

Industry analysis on the broader phishing landscape targeting US finance underscores just how exposed the sector already is, with financial organizations showing markedly higher phishing investigation rates than the global benchmark, driven partly by malware families like Tycoon2FA, Sneaky2FA, and EvilProxy that specialize in exactly this kind of session and token theft according to the ANY.RUN report.

Financial Sector Threat Intelligence
Financial Sector Threat Intelligence (Image Source: ANY.RUN)

This growing reliance on cloud infrastructure abuse is compounding existing pressure on security operations teams that are already stretched thin.

Fresh threat intelligence reporting on emerging phishing kits and supply-chain-linked campaigns can help analysts stay ahead of these evolving tactics before they reach production environments, and teams tracking US-based financial-sector submissions can pivot directly through live indicator queries to see which malicious infrastructure is currently being flagged.

Attack Vector / PlatformAbused Mechanism & ToolingThreat & Operational Impact
Google Cloud PlatformApplication Integration & Cloud StorageDispatches lures from google.com passing SPF, DKIM, and DMARC
Microsoft 365 & AzureTenant display alteration & subdomainsAbuses trusted Microsoft cloud routing to bypass mail security
Amazon Web ServicesMulti-stage AWS S3 redirection gatesHosts credential phishing pages behind dynamic CAPTCHA checks
AiTM Phishing ToolkitsTycoon2FA, Sneaky2FA, and EvilProxyIntercepts session cookies and live tokens to bypass MFA
Defense & MitigationCASB monitoring, FIDO2 MFA, behavior logsCloses visibility gaps on hijacked authentication sessions

Security teams are being urged to move entirely beyond domain-based trust models. Recommended measures include deploying cloud access security brokers to monitor sanctioned and unsanctioned app usage, auditing OAuth and third-party application permissions in Microsoft 365 and Google Workspace, enforcing phishing-resistant MFA such as FIDO2 keys, and treating unusual login geography or access timing as a primary detection signal rather than a secondary one.

Enterprises handling high volumes of sensitive financial data may also want to evaluate dedicated enterprise-grade threat detection support to close the visibility gaps that cloud-based phishing campaigns are specifically designed to exploit.

As generative AI continues to strip away the grammatical and stylistic red flags that once helped users spot phishing attempts, the combination of AI-polished lures and cloud-hosted infrastructure is quickly becoming the default playbook for attackers targeting the financial sector.

Out-of-band verification for financial transactions, strict enforcement of email authentication policies, and continuous behavioral monitoring remain the most reliable countermeasures available today.

Prevent incidents due to slow investigations. Power your Tier 1 with threat intelligence from 15K SOCs: Integrate TI Lookup in your SOC



Source link