Cloudflare Workers Used to Steal MFA Sessions

Securelist · High sophistication
Last updated August 4, 2026

A real multi-stage phishing campaign abused trusted cloud platforms (notably Cloudflare Workers) to make fake login flows look legitimate and to bypass MFA. The attack chained a phishing email, a fake CAPTCHA page on a compromised site, and a browser “pop-up” spoof that captured both credentials and MFA-backed session tokens, then redirected victims to a generic error to reduce suspicion.

Key findings

  • Attackers hosted phishing infrastructure on reputable cloud platforms (Cloudflare Workers, Vercel, Netlify, GitHub Pages) to benefit from domain trust, free tiers, and CDN shielding.
  • The campaign used a multi-stage flow: phishing email → fake CAPTCHA on a compromised site → Cloudflare Workers subdomain with a real CAPTCHA and a service worker → browser-in-the-browser (BitB) fake window wrapping a proxied Microsoft login.
  • The first stage harvested the victim’s email and filtered bots, then redirected to a Cloudflare Workers subdomain.
  • The victim’s email address was passed via the URL hash (after “#”) to avoid being sent in normal network requests and reduce detection.
  • A service worker was registered to intercept and rewrite traffic, routing Microsoft login requests through an attacker-controlled proxy (AitM).
  • The BitB technique displayed a spoofed address bar with a trusted Microsoft URL while intercepting credentials, MFA codes, and session tokens.
  • After successful login, the victim was redirected to a generic error (example: “SessionExpired”) to minimize suspicion.
  • Telemetry (Aug 2025–Jul 2026) showed heavy abuse of cloud domains, led by pages.dev (24.9%), vercel.app (13.8%), github.io (13.7%), and netlify.app (10.0%).

Who’s being targeted

  • Commonly targeted roles: All employees, Executives, Finance, HR, Anyone using Microsoft 365 / webmail / SSO.
  • Affected industries: Cross-industry (any organization using cloud-hosted apps and Microsoft login pages).
  • Attack channels: email, website.
  • Impersonated: Coworker / internal colleague, Cloud-hosted verification page (Cloudflare Workers-hosted content), Microsoft login window (browser-in-the-browser spoof).

Awareness takeaways

  • Don’t trust a link just because it’s HTTPS or hosted on a well-known cloud domain; verify the context and destination.
  • Treat CAPTCHAs that ask you to type personal data (like your email) as suspicious and stop the flow.
  • If a login prompt appears in an unexpected pop-up, close it and navigate to the service manually (type the address yourself).
  • For suspected ‘browser-in-the-browser’ tricks, check the real browser address bar at the top of the window (not the pop-up’s fake address bar).

Red flags to watch for

  • Unexpected document-review request pushing you to click a link
  • CAPTCHA page asks for an email address (unusual for real CAPTCHAs)
  • Redirect chain through unrelated domains before showing any real content
  • You land on an unexpected *.workers.dev page
  • The page carries your email in the URL after a “#” (hash)
  • Unusual background activity that precedes a login prompt
  • Login appears inside a page-rendered pop-up rather than a real browser sign-in flow
  • The pop-up shows a ‘trusted’ URL, but the real browser address bar still shows a different domain
  • After login, you are redirected to a generic error page (e.g., SessionExpired)
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

You get an email from a coworker: “Please review these documents.” You click, and a CAPTCHA page pops up asking for your email. You type your email, hit Continue, and your browser quietly bounces through a compromised site to a Cloudflare Workers link, something like example.workers.dev with your email stuck after a # in the URL. Then a browser-in-the-browser fake Microsoft pop-up appears. It shows a perfect Microsoft login page and a trusted URL in its own little address bar, but it’s just a BitB overlay stealing your password, MFA, and session. If a CAPTCHA asks for your email or a login suddenly appears in a pop-up, stop. Close it, and instead open Microsoft by typing the address into a fresh tab yourself.

Categories

Similar attacks

Fake Install Guides and Helpdesk Calls Drive Attacks

Fake Install Guides and Helpdesk Calls Drive Attacks

This bulletin describes multiple real-world social engineering campaigns where attackers trick people into trusting a familiar screen, like a search result “install guide,” a recruiter outreach, or a helpdesk phone call. The lures push victims to paste commands, install fake software, or reset MFA,…

July 30, 2026
Hotel Wi‑Fi DNS Scam Steals Microsoft 365 Logins

Hotel Wi‑Fi DNS Scam Steals Microsoft 365 Logins

Attackers are taking over hotel and conference Wi‑Fi gateways and changing DNS settings so travelers are silently redirected to fake Microsoft 365 sign-in pages. Victims are then tricked into completing a device-code login that grants attackers a legitimate session token, often bypassing MFA. This…

July 28, 2026
Insurance Phish Turns OTPs Into Live Account Hijacks

Insurance Phish Turns OTPs Into Live Account Hijacks

Researchers observed insurance-themed phishing that doesn’t just steal passwords, it hijacks accounts in real time while the victim is actively logging in. The attack often starts with sponsored Google ads that lead to convincing fake insurance portals, which immediately prompt victims for one-time…

July 25, 2026
OkoBot Tricks Crypto Users Into Running Commands

OkoBot Tricks Crypto Users Into Running Commands

Kaspersky reports an active OkoBot malware campaign targeting Windows users who manage cryptocurrency. Victims are lured via “ClickFix” fake-error pages that trick them into running PowerShell commands, and via GitHub repos posing as legitimate software downloads. The malware then steals wallet…

July 16, 2026
Hijacked Hotel Wi‑Fi Tricks Travelers Into Logins

Hijacked Hotel Wi‑Fi Tricks Travelers Into Logins

Microsoft says a Russian-linked group is abusing hotel and conference Wi‑Fi “captive portals” to trick travelers into entering corporate credentials or installing malware. Victims see what looks like a normal Wi‑Fi login flow, but attackers manipulate DNS/website traffic to redirect them to fake…

August 4, 2026
Hotel Wi‑Fi Hijack Pushes Fake Updates & Phishing

Hotel Wi‑Fi Hijack Pushes Fake Updates & Phishing

Microsoft reported a campaign where attackers abused hotel Wi‑Fi captive portals to manipulate DNS/HTTP traffic and redirect people to attacker-controlled phishing pages. Victims were tricked into installing malware disguised as browser/operating system updates, and some pages redirected users into…

August 3, 2026