Phishers are hijacking legitimate cloud infrastructure

38 pointsposted 6 hours ago
by lschueller

13 Comments

illithid0

4 hours ago

Red teamer here. We've been doing this for a long time for all kinds of evasion. Storing payloads in Azure blob storage, for example, is an amazingly effective way to deliver malware through network filtering controls.

You can look at more of the capabilities we like to use at the LOTS project: https://lots-project.com/

heipei

3 hours ago

Legitimate file hosting services present the biggest total volume of newly discovered phishing pages / unique hostnames. Another (similar) angle is using unrelated legitimate domains which are compromised (think insecure Wordpress) to host phishing sites in subdirectories. A lot of traditional ML scoring and blocking approaches fall flat if the hosting domain is on a very legitimate and hard-to-block domain, such as a government website.

Bender

4 hours ago

Their pie chart almost looks like part of my local DNS configuration. I have not yet blocked github.io or azure however. I built this Unbound DNS configuration file from all the AI submissions in the event I accidentally click on one before noticing the domain.

    local-zone:     "workers.dev." always_null
    local-zone:     "pages.dev." always_null
    local-zone:     "vercel.app." always_null
    local-zone:     "netlify.app." always_null
    local-zone:     "dweb.link." always_null
    local-zone:     "ipfs.io." always_null

    dig +short test.vercel.app
    0.0.0.0

embedding-shape

4 hours ago

> drweb.link."

Considering you have ipfs.io on that list, I wonder if this is a typo for dweb.link actually?

Bender

4 hours ago

That is a typo, I will fix it. Thankyou!

ronsor

an hour ago

If you block github.io, you may as well stop using half this site.

inigyou

4 hours ago

I bet they have an easier time getting past your blacklist filters than non-phishers.

crote

2 hours ago

"Hijacking"? No, those clouds providers are happily hosting phishers.

They simply believe doing the bare minimum of half-hearted anti-abuse is more profitable than doing proper KYC and risking missing out on a legitimate customer or two.

GolfPopper

33 minutes ago

And they are, at present, correct.

ronsor

an hour ago

I'd take the phishers over more KYC invading everything, quite honestly.

crote

20 minutes ago

I don't disagree with you, but I think there's a bit of a difference between setting up an entire cloud infra to the point that you can phish people with it, and making a basic account on a random website to post some comments. Requiring KYC on a site like Reddit is obviously nonsense as at worst someone could make some mean anonymous comments, but we're now seeing Cloudflare being used as an end-to-end platform for sophisticated crime.

You've got to remember that those "free" cloud services are primarily intended as a way to do marketing. You try it out for free because the barrier to entry is so low, then you pay for it when you deploy it to prod. Alternatively: you start with it for free, then are tied to it when your site suddenly gets popular and they start extorting you.

For legitimate use KYC on something like Cloudflare really isn't that big of a deal, in my opinion. I already had to submit my real name and address for my domain registration, and the credit card used to pay for my hosting isn't exactly anonymous either. Heck, when I tried to switch to Hetzner they even asked for a copy of my ID card! We can pretend Cloudflare can't already figure out who I am, but we all know that isn't true.

And of course KYC isn't the only way to solve this. Cloudflare could've also chosen to give new (unpaying / unverified) users a restricted account, which would for example display a Cloudflare ad around it (like .tk domains back in the day), or restrict it to a certain IP range, or only display content after logging in, or after a click-through page. For the attack described in the article they could also force the potential user to supply a subdomain for the service to live on, so it isn't hidden behind Cloudflare's ".workers.dev" and ".pages.dev".

Cloudflare chooses not to do any of this - which in turn makes them the perfect platform for criminals. If that's what they want to, then that's totally fine - but then they should be treated like all the other "bulletproof hosting" organisations out there.

ronsor

7 minutes ago

Hetzner asking for ID is an outlier, probably inspired by German bureaucracy. I've never sent ID to a hosting provider personally. Many domain registrars accept payment in means that don't require ID, and offer WHOIS privacy for free.

I probably would not use Cloudflare if it had KYC simply because I do not want to be interrogated every time I try to do something meaningful online. It is a waste of time because criminals will integrate "verify with stolen identity" into their pipeline tomorrow, while legitimate users are stuck with the headaches.

An interstitial warning page is probably the happy medium, and what ngrok already uses now.

KennyBlanken

an hour ago

I like how you got downvoted for pointing out the truth: behind all this abusive and criminal network activity are a whole slew of service providers happy to not look too closely.

Craigslist's revenue, and his wealth, heavily came from pimps and human traffickers. If anyone thinks they weren't aware of what was going on, they're fooling themselves.

When CL shut those sections down, it only did so because state AGs were starting to make a lot of noise about prosecuting them. Now Craig Newmark makes a lot of noise about all the good things he's doing, and it's primarily for SEO because the only other thing he and the other guy were getting in the news for was running a site that was profiting off human trafficking and prostitution.

All those ads went to Backpages, which most people had never heard of until state DAs start going after them. And how strange that Backpages never did anything on its own about the huge influx of sexual solicitation content...