New Report Warns of 68% Of Actively Serving Phishing Kits Protected by CloudFlare
A recent technical analysis has disclosed significant insights into current phishing operations. Research has identified over 42,000 validated URLs and domains actively involved in phishing kits, command-and-control infrastructure, and malicious payload…
A recent technical analysis has disclosed significant insights into current phishing operations. Research has identified over 42,000 validated URLs and domains actively involved in phishing kits, command-and-control infrastructure, and malicious payload delivery systems.
The complexity and organization of these operations represent a progression from traditional phishing attempts. These modern campaigns are characterized by a level of efficiency and structure akin to legitimate technology companies.
The threat environment has evolved from individual attacks to coordinated criminal enterprises, utilizing professional infrastructure management, reliable uptime, and sophisticated evasion techniques comparable to enterprise-grade security systems.
Security analysts from SicuraNext have observed a high level of operational maturity within these campaigns. A mean DNS resolution rate of 96.16% was reported, indicating the stability and maintenance of the domains involved.
A recent technical analysis has disclosed significant insights into current phishing operations.
SicuraNext researchers also noted that Cloudflare is a major infrastructure provider for these phishing operations. Analysis shows that 17,202 out of 25,305 tracked malicious domains, equating to 68% of the phishing infrastructure, operate through Cloudflare's network.
This concentration arises because Cloudflare's free tier provides threat actors with no upfront cost, alongside DDoS protection and proxy services that conceal actual hosting servers.
MFA Bypass Infrastructure and Defense Evasion
Phishing-as-a-Service platforms, such as EvilProxy and Tycoon 2FA, present significant developments. These platforms function as adversary-in-the-middle proxies, intercepting user sessions and capturing session cookies, thereby bypassing multi-factor authentication protections.
These platforms employ evasion technologies, including geofencing to block security researchers by IP range, user-agent-based cloaking to restrict content to certain devices, and detection of developer tools to prevent functionality when inspection tools are opened. Cloudflare CAPTCHA filters are also used to exclude automated security scanners.
The analysis identified 20 distinct phishing clusters with shared infrastructure fingerprints, rotated IP ranges, identical registrars, and consistent evasion patterns, signifying coordinated professional operations rather than random attacks.
Based on reporting by Cyber Security News.
