Phishing Campaigns Abuse Trusted Platforms and Legitimate Workflows to Evade Detection
Multiple campaigns are abusing legitimate cloud and platform workflows to make phishing and fraud harder to detect. Attackers are generating real Apple and PayPal invoice/dispute emails and embedding scam phone numbers in user-controlled fields (e.g., “seller notes”), resulting in messages that carry valid DKIM signatures and originate from high-reputation domains; this “DKIM replay” style abuse bypasses many email controls because authentication validates the sender domain, not the safety of the embedded content. In parallel, threat actors are leveraging free Google Firebase developer accounts to host brand-mimicking phishing pages on trusted firebaseapp.com / web.app subdomains, increasing delivery and click-through rates by exploiting domain reputation and common allowlisting of Google infrastructure.
A separate but related social-engineering technique targets Telegram users by manipulating Telegram’s official authentication workflows to obtain fully authorized sessions rather than simply stealing passwords. Victims are lured to Telegram-lookalike pages (often on ephemeral domains) that prompt QR scanning or phone-number entry; user interaction triggers a real login attempt initiated by the attacker, and once the victim approves the authorization prompt on their device, the attacker gains persistent account access and can pivot to follow-on attacks via the victim’s contacts. These incidents collectively highlight a shift toward “living off trusted services,” where adversaries avoid compromising vendors and instead weaponize legitimate features, trusted domains, and sanctioned authentication flows to reduce detection and increase victim compliance.

Get ahead of threats like this
Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
How this story unfolded
5 events from the most recent confirmed update back to the earliest known activity.
Researchers disclose phishing via legitimate Apple and PayPal invoice emails
Kaseya reported a campaign in which attackers abused real Apple and PayPal invoicing or dispute workflows to send digitally signed emails containing scam phone numbers in user-controlled fields. The messages could pass DKIM/DMARC checks and be replayed or forwarded to victims while retaining trust signals from the original sender domains.
Technical details published on Telegram campaign's reusable framework
Researchers disclosed that the Telegram operation used a centralized, configuration-driven phishing framework with runtime instructions fetched from a server, attacker-controlled Telegram API credentials, multilingual support, and rapid domain rotation. The design enabled high-volume deployment and quick replacement of blocked lookalike domains.
Telegram phishing campaign re-emerges abusing real authorization flows
CYFIRMA reported a renewed Telegram phishing operation that tricked users into approving legitimate login requests from attacker-controlled devices via fake Telegram-branded pages. Instead of stealing passwords, the campaign obtained persistent authorized sessions after victims approved in-app prompts or QR-based logins.
Surge observed in Firebase-hosted phishing campaigns
In early February 2026, analysts observed an increase in phishing activity using abused Firebase projects, with attackers rapidly creating replacement projects when prior ones were suspended. The lures used urgent fraud alerts and free-item offers to drive credential theft.
Analysts identify phishing campaign abusing free Firebase hosting
Unit 42 reported identifying a phishing operation in early February 2026 that used free Google Firebase developer accounts to host brand-impersonation login pages on trusted firebaseapp.com and web.app subdomains. The campaign benefited from Google-hosted domain reputation to evade some email and web security filtering.
Related entities
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Sources
4 references tracked. Mallory keeps watching after this page renders.
Telegram Phishing Campaign Hijacks Accounts by Abusing Trust
securityonline.info
Open sourceHackers Exploit Legitimate Apple and PayPal Invoice Emails in DKIM Replay Attacks
cybersecuritynews.com
Open sourceNew Telegram Phishing Attack Abuses Authentication Workflows to Obtain Full Authorized User Sessions - Cyber Security News
cybersecuritynews.com
Open sourceHackers Leveraging Free Firebase Developer Accounts to Send Phishing Emails
cybersecuritynews.com
Open sourceSee the full picture, correlated to your attack surface.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.


