How hackers "hide" behind Google, AWS and Microsoft to hit banks

Published Reading time: 3 minutes Scams & Phishing Attacks

Attackers are increasingly using trusted cloud services to stage phishing attacks against financial institutions. Microsoft Azure, Google Firebase, Google Cloud Storage, Amazon Web Services, and Cloudflare now host parts of the infrastructure for these campaigns, making the malicious traffic look like regular corporate activity.

How hackers "hide" behind Google, AWS and Microsoft to hit banks - Image 1

Researchers describe this trend as Trusted Infrastructure Phishing . Instead of relying solely on their own domains, attackers use legitimate services to distribute messages, redirect, and steal login credentials.

Fake Microsoft Authentication Page
Fake Microsoft Authentication Page (Image Source: ANY.RUN)

How cloud services are utilized

Financial institutions use cloud storage, document sharing tools, and partner platforms every day, allowing attackers to leverage off-the-shelf infrastructure that already has the trust of well-known providers.

In recent campaigns, they exploited the legitimate “Send Email” feature of Google Cloud Application Integration to send phishing emails from google.com addresses. This allowed the emails to pass SPF, DKIM, and DMARC checks, which typically help detect spoofed senders.

Those who clicked on the link were initially taken through Google Cloud Storage and CAPTCHA pages before landing on a fake Microsoft 365 login page hosted on AWS S3. This chain of redirects makes it difficult for both automated screening tools and users trying to identify the scam.

Similar techniques have been identified in Microsoft 365 environments. There, perpetrators change the display names of tenants and route phishing messages through Microsoft's own infrastructure, maintaining the appearance of legitimate communication.

Financial Sector Threat Intelligence
Financial Sector Threat Intelligence (Image Source: ANY.RUN)

Token theft and MFA bypass

Cloud service abuse is not limited to sending emails. Attackers are embedding adversary-in-the-middle (AiTM) phishing kits into legitimate content delivery networks and cloud subdomains. These tools interpose themselves between the user and the actual service and capture login credentials, session cookies, and active authentication tokens.

Thus, an attack can bypass multi-factor authentication (MFA) as the attacker steals the active session instead of relying on a password alone. For banks and other financial companies, a compromised session can provide access to sensitive transaction data.

Tycoon2FA, Sneaky2FA, and EvilProxy are reported as malware and phishing tools that specialize in stealing sessions and tokens. According to a report by ANY.RUN, financial institutions in the US experience higher rates of phishing investigations than the global average.

The need for post-click tracking

Traditional email gateways and domain reputation tools have limited effectiveness when the infrastructure is legitimate. Therefore, security teams need to look at behavioral signs after the message is delivered, such as click data, redirect chains, and unusual login attempts after opening a link.

Recommended defenses include monitoring via a Cloud Access Security Broker (CASB), auditing OAuth permissions and third-party apps in Microsoft 365 and Google Workspace, and using phishing-resistant MFA, such as FIDO2 keys. An unusual geographic location or login time should also be a key signal for further investigation.

The use of artificial intelligence makes phishing messages more convincing, reducing the grammatical and stylistic errors that often give away a scam. The combination of well-crafted messages and infrastructure hosted on trusted cloud services increases the pressure on financial institutions' security teams.

Verifying transactions through a different channel, strictly enforcing email control policies, and continuously monitoring account behavior remain key countermeasures, according to the analysis.

Hacks.gr on Google Set it as a preferred source for cybersecurity updates.
Preferred source

READ ALSO

Recommended readings from Hacks.gr to continue.

Participate in the discussion

Comments should remain on topic. Your email address will not be published.

0 / 2000

0 / 50

Your comments will not be published if:

  • 1. They cause "DoS" to the community with irrelevant or repetitive comments.
  • 2. They try to "phish" other users' information.
  • 3. They contain "zero-day" insults and slurs.
  • 4. Contain "malware" advertisements for products or services.
  • 5. Your comments should be sweet and friendly, not like malicious cookies trying to mislead us!