Cloud Infrastructure phishing: when trusted domains become part of the attack chain
Threat actors are increasingly abusing legitimate cloud services to make phishing emails and malicious links appear more trustworthy. Check Point observed 9,394 phishing emails targeting approximately 3,200 customers over a two-week period, using Google Cloud Application Integration and Google-hosted infrastructure to redirect victims to a fake Microsoft login page. The campaign was not associated with a specific CVE.
A legitimate domain is no longer sufficient evidence that the content behind it is safe. Instead of building an entire phishing operation on newly registered or low-reputation domains, attackers increasingly abuse services enterprises already trust, including Google Cloud, Microsoft Azure, Amazon Web Services, Google Firebase, and Cloudflare.
The key distinction is that these cloud platforms are not necessarily compromised. In the campaign analyzed by Check Point, Google confirmed that attackers had abused a legitimate workflow capability in Application Integration rather than breaching Google Cloud infrastructure.
For enterprises, this changes the trust model. Security teams can no longer assess email and URL risk primarily through sender reputation or domain reputation.
What happened in the Google Cloud phishing campaign?
Check Point identified a phishing campaign in which threat actors used the Send Email task within Google Cloud Application Integration to deliver messages designed to resemble legitimate Google notifications. During approximately two weeks of observation, researchers recorded 9,394 phishing emails targeting around 3,200 customers.

The emails were sent from the legitimate address noreply-application-integration@google.com and commonly impersonated familiar business notifications, such as voicemail alerts, document access requests, and file-sharing messages.
This made the initial message more credible than conventional phishing emails sent from an obviously suspicious domain.
The attack chain described by Check Point involved three main stages:
The victim received an email delivered through legitimate Google Cloud infrastructure.
The initial link pointed to storage.cloud.google.com, then redirected to content hosted on googleusercontent.com, where a fake CAPTCHA was displayed to make automated analysis more difficult.
The victim was ultimately redirected to a fake Microsoft login page hosted on a domain that did not belong to Microsoft, where credentials could be harvested.
Google later said it had blocked several campaigns abusing the email notification functionality of Google Cloud Application Integration and introduced additional safeguards intended to reduce abuse.
👉 A similar trust-abuse pattern has also appeared in Microsoft-related campaigns. IPSIP previously analyzed a phishing campaign abusing Azure Monitor alerts, demonstrating how legitimate cloud services can be incorporated into attack chains to make malicious messages appear more credible.
What numbers show that the risk extends beyond the financial sector?
The industry distribution observed by Check Point suggests that trusted-infrastructure phishing is not limited to banking or financial services. Manufacturing and industrial organizations accounted for 19.6% of the observed targets, while technology and SaaS represented 18.9% and finance, banking, and insurance accounted for 14.8%.
Target sector | Share |
Manufacturing / Industrial | 19.6% |
Technology / SaaS | 18.9% |
Finance / Banking / Insurance | 14.8% |
Professional Services / Consulting | 10.7% |
Retail / Consumer | 9.1% |
Geographically, the United States accounted for 48.6% of observed activity, while Asia-Pacific represented 20.7%, indicating that this attack model is not confined to North America.
A broader identity-security problem is also reflected in the Google Cloud Threat Horizons Report H1 2026. Based on incidents handled by Mandiant during the second half of 2025, identity-related issues played a role in 83% of compromises involving major cloud and SaaS environments. The report also noted that 5% of incidents involved abuse of cloud infrastructure to support follow-on attacks such as phishing and smishing.
For Vietnamese organizations, this trend should be viewed alongside the wider regional increase in account compromise, identity abuse, and online fraud. IPSIP’s Vietnam Cybersecurity Landscape Q2 2026 provides additional context on how credential theft and identity-based attacks are increasingly intertwined with infrastructure security risks.
Why does cloud infrastructure make phishing harder to detect?
This attack model weakens a long-standing assumption in email security: that a high-reputation domain is generally a lower-risk indicator.
In the Check Point campaign, the email genuinely passed through Google infrastructure. As a result, defenses that rely heavily on sender reputation, trusted-domain lists, or basic anti-spoofing checks may fail to identify the entire attack chain.
Attackers can also layer multiple evasion techniques, including:
legitimate cloud-hosted URLs in the initial stage;
multiple redirects;
CAPTCHA pages designed to distinguish human users from automated scanners;
cloned Microsoft authentication interfaces;
Phishing-as-a-Service infrastructure that enables rapid deployment.
ANY.RUN has reported that phishing platforms such as Tycoon2FA, Sneaky2FA, and EvilProxy have used or hidden behind infrastructure associated with Cloudflare, Google Firebase, AWS CloudFront, Microsoft, and other cloud providers.
The risk increases further when phishing evolves from password theft into Adversary-in-the-Middle (AiTM) attacks.
Organizations should therefore consider stronger authentication methods such as phishing-resistant MFA based on FIDO2 and WebAuthn instead of treating all forms of MFA as equivalent.
What should enterprises do immediately?
Security controls should move from a “trust the domain” model toward continuous evaluation of identity, behavior, URLs, and post-login activity.
A Google or Microsoft URL should be treated as one signal in the security decision, not as proof that the underlying content is legitimate.
Priority action checklist:
Review emails that request Microsoft 365 or Google Workspace re-authentication, even when they originate from a trusted domain.
Deploy phishing-resistant MFA, such as FIDO2 security keys or passkeys, especially for administrators and users with access to sensitive data.
Review OAuth applications, third-party applications, and unusual consent permissions.
Monitor sign-ins from unusual locations, devices, ASNs, or time patterns.
Correlate suspicious URL clicks with subsequent login or session-creation activity.
Ensure the SOC can analyze full redirect chains rather than only the first URL.
Revoke active sessions and tokens when an account is suspected of credential exposure.
Train employees to verify login requests based on context rather than relying on sender names, logos, or trusted domains.
Microsoft also recommends combining user awareness, anti-phishing controls, email-security configuration, and network and browser protections when defending against multi-stage phishing campaigns.
What does the IPSIP Vietnam's expert perspective show?
A compromised Microsoft 365 or Google Workspace account may expose corporate email, cloud data, shared documents, and business communications. If an attacker steals a valid authentication token, a password reset alone may not immediately invalidate an active session.
Security controls should focus more heavily on identity and behavioral signals rather than domain reputation alone. Enterprises should also correlate email telemetry, identity logs, endpoint signals, and cloud logs so that attack chains are investigated as connected events instead of isolated alerts.
Cloud infrastructure phishing reflects an important shift in how attackers exploit trust.
When the sender, URL, or parts of the delivery infrastructure belong to legitimate cloud providers, defenses based primarily on domain reputation can create blind spots.
For Vietnamese enterprises using Microsoft 365, Google Workspace, and public cloud platforms, security priorities should increasingly center on identity protection, phishing-resistant MFA, session monitoring, and rapid response to suspected account compromise.
References











Comments