Skip to main content
Mallory
Back to intelligence
phishing-campaign-intelligencecredential-access-methodcloud-misconfigurationidentity-authentication-vulnerability

Threat Actors Abuse Trusted Cloud and Ad Platforms for Multi-Stage Phishing and Scam Delivery

Updated 3mo agoFirst seen Feb 5, 20263 sources

Threat actors are increasingly using trusted platforms—including cloud hosting and major ad networks—to deliver multi-stage phishing and scam campaigns that evade traditional URL and domain reputation controls. Recent activity includes a three-step malvertising chain delivered via Facebook paid ads that redirects victims through a decoy site (e.g., a fake Italian restaurant page) before landing on a tech support scam (TSS) kit hosted on Microsoft Azure infrastructure (including web.core.windows.net). Researchers reported rapid infrastructure churn, with 100+ domains rotated in seven days, and targeting focused on U.S. users with activity concentrated on weekdays.

Parallel enterprise-focused campaigns are hosting phishing infrastructure on Microsoft Azure Blob Storage, Google Firebase, and AWS CloudFront, using redirect chains, CAPTCHA gates, and QR codes to bypass automated analysis and email defenses. Analysis highlighted the use of Adversary-in-the-Middle (AiTM) phishing-as-a-service kits—Tycoon2FA, Sneaky2FA, and EvilProxy—to steal credentials and session tokens even when MFA is enabled. Separately, researchers documented a “clean email” approach to steal Dropbox credentials: benign-looking procurement-themed emails deliver PDF attachments that hide clickable elements (e.g., via AcroForms and FlateDecode), which then route victims to a second-stage file hosted on Vercel Blob and ultimately to a fake Dropbox login page that captures credentials and collects victim telemetry (IP address, location, and device details).

Share:
Threat Actors Abuse Trusted Cloud and Ad Platforms for Multi-Stage Phishing and Scam Delivery
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

3 events from the most recent confirmed update back to the earliest known activity.

3 EVENTS
Feb 5, 20264mo ago

Facebook malvertising chain delivering tech support scam disclosed

Gen Threat Labs reported a three-step malvertising campaign abusing Facebook paid ads to redirect U.S. users through decoy sites to scareware-style tech support scam pages hosted on Microsoft Azure. The operators were said to have rotated more than 100 domains over seven days and to have run the campaign mainly on weekdays.

Feb 4, 20264mo ago

Abuse of Microsoft and Google platforms to target enterprise users reported

Threat actors were reported abusing trusted Microsoft and Google platforms as part of attacks against enterprise users. The reference indicates a distinct campaign or technique disclosure, but does not provide a more specific event date than the publication date.

Feb 2, 20264mo ago

Dropbox phishing campaign using clean emails and PDF lures reported

A phishing campaign targeting Dropbox users was identified using clean-looking emails and PDF attachments or links to steal account credentials. The activity was publicly reported by Hackread, but no earlier concrete event date is provided in the reference.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

18 LINKEDOpen in app
Affected products
3 linked
TelegramCloudfrontCloudflare Cdn
Organizations
12 linked
Microsoft CorporationMeta PlatformsGen Threat LabsAmazon Web ServicesForcepointCloudflareDropboxVercelAny.RunTelegramHackread.comGoogle
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

Threat Actors Abuse Trusted Cloud and Ad Platforms for Multi-Stage Phishing and Scam Delivery | Mallory