How legitimate cloud platforms enable phishers to bypass MFA

2026-08-07T20:51:46Z6aa1e9761a5f62e0837181776b83b82b7eafda6db3957a63f186d84f2fc72028
AfricaBitLocker-extortionCentral-AsiaCloudflare-WorkersGenieLockerGitHub-PagesIPFSMFA-bypassMSSQL-abuse่ัว?Middle-EastNetlifyRDPSoutheast-AsiaVerceladversary-in-the-middlebackdoorcloud-platform-abusecredential-dumpingcyber-espionagekeyloggingmemory-resident-malwarenetwork-scanningphishingransomwareservice-workers

What happened

Kaspersky Securelist reporting covers contemporary phishing, MFA bypass, cyber-espionage, ransomware, and targeted intrusion activity. Highlights include adversary-in-the-middle phishing hosted on legitimate cloud platforms, memory-resident backdoors targeting Central Asia, GenieLocker ransomware affecting Windows/Linux/ESXi, Mirage Kitten tools targeting the Middle East and Africa, BitLocker-based extortion, Outlook/Microsoft Graph and DNS-based C2, supply-chain abuse of the ViPNet update system, and data theft campaigns against Southeast Asian government entities.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
kaspersky_securelist
Record identifier
6aa1e9761a5f62e0837181776b83b82b7eafda6db3957a63f186d84f2fc72028
Enrichment time
2026-08-07T20:51:46Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · How legitimate cloud platforms enable phishers to bypass MFA · Baitaphish