How legitimate cloud platforms enable phishers to bypass MFA
2026-08-07T20:51:46Z•6aa1e9761a5f62e0837181776b83b82b7eafda6db3957a63f186d84f2fc72028
AfricaBitLocker-extortionCentral-AsiaCloudflare-WorkersGenieLockerGitHub-PagesIPFSMFA-bypassMSSQL-abuse่ัว?Middle-EastNetlifyRDPSoutheast-AsiaVerceladversary-in-the-middlebackdoorcloud-platform-abusecredential-dumpingcyber-espionagekeyloggingmemory-resident-malwarenetwork-scanningphishingransomwareservice-workers
What happened
Kaspersky Securelist reporting covers contemporary phishing, MFA bypass, cyber-espionage, ransomware, and targeted intrusion activity. Highlights include adversary-in-the-middle phishing hosted on legitimate cloud platforms, memory-resident backdoors targeting Central Asia, GenieLocker ransomware affecting Windows/Linux/ESXi, Mirage Kitten tools targeting the Middle East and Africa, BitLocker-based extortion, Outlook/Microsoft Graph and DNS-based C2, supply-chain abuse of the ViPNet update system, and data theft campaigns against Southeast Asian government entities.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- kaspersky_securelist
- Record identifier
- 6aa1e9761a5f62e0837181776b83b82b7eafda6db3957a63f186d84f2fc72028
- Enrichment time
- 2026-08-07T20:51:46Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.