Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
phishing-campaign-intelligencecredential-access-methoddefense-evasion-methodcommand-and-control-method

Phishing Attacks Leveraging Cloudflare Pages and Modern Phishing Kits

Updated 3mo agoFirst seen Dec 15, 20253 sources

Threat actors are increasingly abusing free web hosting services such as Cloudflare Pages to host phishing portals that impersonate banking, insurance, and healthcare organizations. These phishing sites are designed to harvest sensitive information including credentials, security questions, and multifactor authentication codes. Attackers benefit from the speed, scale, and resilience provided by free hosting, as well as the use of mainstream messaging platforms like Telegram for exfiltration, making detection and takedown efforts more challenging for defenders.

Modern phishing kits have evolved into sophisticated platforms that enable even low-skilled threat actors to deploy convincing credential-harvesting sites rapidly. These kits often include features such as admin panels, real-time credential delivery, proxy capabilities for MFA bypass, and antibot systems to evade security researchers. The accessibility and advanced capabilities of these kits, combined with the use of free hosting and messaging services, have significantly lowered the barrier to entry for large-scale phishing campaigns targeting organizations and individuals alike.

Share:
Phishing Attacks Leveraging Cloudflare Pages and Modern Phishing Kits
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

3 events from the most recent confirmed update back to the earliest known activity.

3 EVENTS
Dec 18, 20256mo ago

Flare identifies live cloud-native phishing infrastructure targeting major platforms

Flare Research reported live phishing operations targeting Gmail, Facebook, and Microsoft 365 using BitM, AiTM, and reverse-proxy techniques to steal sessions and bypass MFA. The investigation found scalable, automated infrastructure across multiple hosting providers, shared IOCs, and reported findings to relevant CERTs.

Dec 15, 20256mo ago

Research documents mature phishing-kit ecosystem and Telegram-enabled operations

Analysis published on phishing kits described a mature Phishing-as-a-Service market with subscription pricing, Telegram-based distribution and exfiltration, and tools such as Evilginx and EvilProxy enabling AiTM attacks and MFA bypass. The research highlighted rapid redeployment, short-lived infrastructure, and phishing's continued role as a major initial access vector.

Threat actors begin abusing Cloudflare Pages for phishing portals

A phishing campaign used the free Cloudflare Pages service to host fake login pages impersonating banking, insurance, and healthcare organizations. The operation also used compromised redirectors and Telegram-based exfiltration to steal credentials, security answers, and MFA codes while evading traditional detection.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

26 LINKEDOpen in app
Organizations
25 linked
CloudflareMicrosoft CorporationGoogleDigitaloceanProton66VultrMeta PlatformsExploitHetznerALEXHOSTDataCamp LimitedUltahostLinodeFlare ResearchMalwarebytesXSSInternational Business MachinesOktaKnowbe4TelegramFlareEvilginxNetlifyCaffeineEvilProxy
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.