Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
phishing-campaign-intelligenceidentity-impersonation-fraudidentity-authentication-vulnerabilitycredential-access-method

Phishing Campaigns Abuse Trusted Platforms and Legitimate Workflows to Evade Detection

Updated 3mo agoFirst seen Feb 10, 20264 sources

Multiple campaigns are abusing legitimate cloud and platform workflows to make phishing and fraud harder to detect. Attackers are generating real Apple and PayPal invoice/dispute emails and embedding scam phone numbers in user-controlled fields (e.g., “seller notes”), resulting in messages that carry valid DKIM signatures and originate from high-reputation domains; this “DKIM replay” style abuse bypasses many email controls because authentication validates the sender domain, not the safety of the embedded content. In parallel, threat actors are leveraging free Google Firebase developer accounts to host brand-mimicking phishing pages on trusted firebaseapp.com / web.app subdomains, increasing delivery and click-through rates by exploiting domain reputation and common allowlisting of Google infrastructure.

A separate but related social-engineering technique targets Telegram users by manipulating Telegram’s official authentication workflows to obtain fully authorized sessions rather than simply stealing passwords. Victims are lured to Telegram-lookalike pages (often on ephemeral domains) that prompt QR scanning or phone-number entry; user interaction triggers a real login attempt initiated by the attacker, and once the victim approves the authorization prompt on their device, the attacker gains persistent account access and can pivot to follow-on attacks via the victim’s contacts. These incidents collectively highlight a shift toward “living off trusted services,” where adversaries avoid compromising vendors and instead weaponize legitimate features, trusted domains, and sanctioned authentication flows to reduce detection and increase victim compliance.

Share:
Phishing Campaigns Abuse Trusted Platforms and Legitimate Workflows to Evade Detection
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

5 events from the most recent confirmed update back to the earliest known activity.

5 EVENTS
Feb 9, 20264mo ago

Researchers disclose phishing via legitimate Apple and PayPal invoice emails

Kaseya reported a campaign in which attackers abused real Apple and PayPal invoicing or dispute workflows to send digitally signed emails containing scam phone numbers in user-controlled fields. The messages could pass DKIM/DMARC checks and be replayed or forwarded to victims while retaining trust signals from the original sender domains.

Technical details published on Telegram campaign's reusable framework

Researchers disclosed that the Telegram operation used a centralized, configuration-driven phishing framework with runtime instructions fetched from a server, attacker-controlled Telegram API credentials, multilingual support, and rapid domain rotation. The design enabled high-volume deployment and quick replacement of blocked lookalike domains.

Telegram phishing campaign re-emerges abusing real authorization flows

CYFIRMA reported a renewed Telegram phishing operation that tricked users into approving legitimate login requests from attacker-controlled devices via fake Telegram-branded pages. Instead of stealing passwords, the campaign obtained persistent authorized sessions after victims approved in-app prompts or QR-based logins.

Feb 1, 20265mo ago

Surge observed in Firebase-hosted phishing campaigns

In early February 2026, analysts observed an increase in phishing activity using abused Firebase projects, with attackers rapidly creating replacement projects when prior ones were suspended. The lures used urgent fraud alerts and free-item offers to drive credential theft.

Analysts identify phishing campaign abusing free Firebase hosting

Unit 42 reported identifying a phishing operation in early February 2026 that used free Google Firebase developer accounts to host brand-impersonation login pages on trusted firebaseapp.com and web.app subdomains. The campaign benefited from Google-hosted domain reputation to evade some email and web security filtering.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

9 LINKEDOpen in app
Affected products
4 linked
IosIosTelegramPaypal
Organizations
5 linked
CYFIRMATelegramApplePalo Alto NetworksGoogle
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

Phishing Campaigns Abuse Trusted Platforms and Legitimate Workflows to Evade Detection | Mallory