Researchers describe this trend as Trusted Infrastructure Phishing . Instead of relying solely on their own domains, attackers use legitimate services to distribute messages, redirect, and steal login credentials.

How cloud services are utilized
Financial institutions use cloud storage, document sharing tools, and partner platforms every day, allowing attackers to leverage off-the-shelf infrastructure that already has the trust of well-known providers.
In recent campaigns, they exploited the legitimate “Send Email” feature of Google Cloud Application Integration to send phishing emails from google.com addresses. This allowed the emails to pass SPF, DKIM, and DMARC checks, which typically help detect spoofed senders.
Those who clicked on the link were initially taken through Google Cloud Storage and CAPTCHA pages before landing on a fake Microsoft 365 login page hosted on AWS S3. This chain of redirects makes it difficult for both automated screening tools and users trying to identify the scam.
Similar techniques have been identified in Microsoft 365 environments. There, perpetrators change the display names of tenants and route phishing messages through Microsoft's own infrastructure, maintaining the appearance of legitimate communication.

Token theft and MFA bypass
Cloud service abuse is not limited to sending emails. Attackers are embedding adversary-in-the-middle (AiTM) phishing kits into legitimate content delivery networks and cloud subdomains. These tools interpose themselves between the user and the actual service and capture login credentials, session cookies, and active authentication tokens.
Thus, an attack can bypass multi-factor authentication (MFA) as the attacker steals the active session instead of relying on a password alone. For banks and other financial companies, a compromised session can provide access to sensitive transaction data.
Tycoon2FA, Sneaky2FA, and EvilProxy are reported as malware and phishing tools that specialize in stealing sessions and tokens. According to a report by ANY.RUN, financial institutions in the US experience higher rates of phishing investigations than the global average.
The need for post-click tracking
Traditional email gateways and domain reputation tools have limited effectiveness when the infrastructure is legitimate. Therefore, security teams need to look at behavioral signs after the message is delivered, such as click data, redirect chains, and unusual login attempts after opening a link.
Recommended defenses include monitoring via a Cloud Access Security Broker (CASB), auditing OAuth permissions and third-party apps in Microsoft 365 and Google Workspace, and using phishing-resistant MFA, such as FIDO2 keys. An unusual geographic location or login time should also be a key signal for further investigation.
The use of artificial intelligence makes phishing messages more convincing, reducing the grammatical and stylistic errors that often give away a scam. The combination of well-crafted messages and infrastructure hosted on trusted cloud services increases the pressure on financial institutions' security teams.
Verifying transactions through a different channel, strictly enforcing email control policies, and continuously monitoring account behavior remain key countermeasures, according to the analysis.
Your comments will not be published if: