Security News > 2022 > August > Phishing attack abuses Microsoft Azure, Google Sites to steal crypto

A new large-scale phishing campaign targeting Coinbase, MetaMask, Kraken, and Gemini users is abusing Google Sites and Microsoft Azure Web App to create fraudulent sites.
Posting links to phishing pages on various legitimate sites aims to increase traffic and boost the malicious site's search engine rankings.
Because the phishing sites are hosted in Microsoft and Google services, they aren't flagged by automated moderator systems, allowing promotional messages to stay in the comment section for longer.
Google Sites is a free web page creation tool, part of Google's online service suite, allowing users to create websites and host them on Google Cloud or other providers.
The sites are just landing pages, and their visitors are redirected to the actual phishing sites when they click on the "Login" buttons.
For the crypto exchange phishing pages, the threat actors attempt to steal their login credentials.
News URL
Related news
- Microsoft: Hackers steal emails in device code phishing attacks (source)
- Microsoft Identifies 3,000 Leaked ASP.NET Keys Enabling Code Injection Attacks (source)
- Week in review: Exploited 7-Zip 0-day flaw, crypto-stealing malware found on App Store, Google Play (source)
- Microsoft Uncovers Sandworm Subgroup's Global Cyber Attacks Spanning 15+ Countries (source)
- North Korea targets crypto developers via NPM supply chain attack (source)
- Microsoft: Russian-Linked Hackers Using 'Device Code Phishing' to Hijack Accounts (source)
- ⚡ THN Weekly Recap: Google Secrets Stolen, Windows Hack, New Crypto Scams and More (source)
- Microsoft spots XCSSET macOS malware variant used for crypto theft (source)
- Darktrace: 96% of Phishing Attacks in 2024 Exploited Trusted Domains Including SharePoint & Zoom Docs (source)
- Phishing attack hides JavaScript using invisible Unicode trick (source)