{"id":11294,"date":"2026-03-12T10:03:51","date_gmt":"2026-03-12T10:03:51","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2026\/03\/12\/hackers-leveraging-cloudflare-anti-bot-features-to-steal-microsoft-365-credentials\/"},"modified":"2026-03-12T10:03:51","modified_gmt":"2026-03-12T10:03:51","slug":"hackers-leveraging-cloudflare-anti-bot-features-to-steal-microsoft-365-credentials","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2026\/03\/12\/hackers-leveraging-cloudflare-anti-bot-features-to-steal-microsoft-365-credentials\/","title":{"rendered":"Hackers Leveraging Cloudflare Anti-Bot Features to Steal Microsoft 365 Credentials"},"content":{"rendered":"<p>    Hackers Leveraging Cloudflare Anti-Bot Features to Steal Microsoft 365 Credentials<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>A sophisticated <a href=\"https:\/\/cybersecuritynews.com\/new-oauth-based-attack\/\" target=\"_blank\" rel=\"noreferrer noopener\">Microsoft 365 credential harvesting campaign<\/a> that weaponizes Cloudflare\u2019s own protective features to evade detection and silently steal user login data.<\/p>\n<p>The campaign demonstrates a growing and troubling trend: threat actors turning the very tools designed to defend websites into shields for malicious infrastructure.<\/p>\n<p>Platforms like Cloudflare are widely trusted for their anti-bot protections, content delivery capabilities, and DDoS mitigation. However, these same features, including human verification checks, IP filtering, and user-agent inspection, can inadvertently obstruct security researchers and automated scanning tools from identifying malicious sites in a timely manner. Attackers in this campaign exploited exactly that blind spot.<\/p>\n<p>The campaign uncovered by Domaintools was anchored by the domain securedsnmail[.]com, which served as the initial entry point for victims. Once a user landed on the page, a multi-layered gatekeeping system went to work before any credential theft occurred.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEg-zJrP8Z3EQbMHkAbDk15gWATM2dh2TlegNECMV_x81RFE9LhXYfzCIXSe0GnZiylOP6Ovy-MnjLkG5dBQDg69u8RwCcwXOSyUWA9_RESRo2NrqjuWmoX0ACX32X1ANs-G7FGCoRU-O0nxKk7jk9XcKmCclzIWCiOAdyqdvndWwbZZ4Do4h5FCr_c-pqAK\/w640-h522\/cloudspoof.webp?ssl=1\" alt=\"\"><\/figure>\n<\/div>\n<p>The site\u2019s first line of defense was a <a href=\"https:\/\/cybersecuritynews.com\/cloudflare-massive-outage-details\/\" target=\"_blank\" rel=\"noreferrer noopener\">Cloudflare human verification (Turnstile) check<\/a>, which immediately filtered out automated crawlers. But the attackers didn\u2019t stop there.<\/p>\n<p>The phishing page also queried the visitor\u2019s IP address via <code>api.ipify[.]org<\/code> and cross-referenced it against a hardcoded blocklist that included IP ranges belonging to major security vendors such as Palo Alto Networks and FireEye, as well as cloud infrastructure from AWS and Google.<\/p>\n<p>If a visitor\u2019s browser carried a suspicious user-agent string, such as those associated with Googlebot, Bingbot, AhrefsBot, or Twitterbot, the page would dynamically replace itself with a convincing fake \u201c404 Not Found\u201d error, preventing the site from being indexed or flagged by security scanners.<\/p>\n<p>Any visitor who cleared these checks was then funneled through an obfuscated credential harvesting script. The core theft logic was concealed inside a custom virtual machine function (<code>e_d007dc<\/code>) that interpreted an array of encoded instructions, making static code analysis ineffective.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEisyt8vsz5gf3jDCL_UlgnK3tdVHwydk7CgeK1yC0gt40-TGVMszoE1SJybF9MX1FXG8AvOYpoaQQgsHoszkY9skpq1XIkV24zLnrdnyqOOA36gCimmtAMKNYYt8SavXJqVRBlHtNtd1Jw0wIP_FyttrgLJuktjucwb6F4NTDTjjbB4f383u3YAuGWBB1Hd\/s16000\/ed007dc.webp?ssl=1\" alt=\"\"><\/figure>\n<\/div>\n<p>If the gatekeeping logic detected a security tool mid-session, the VM quietly redirected the destination URL to a legitimate domain, such as Google.com, neutralizing any forensic footprint.<\/p>\n<p><a href=\"https:\/\/dti.domaintools.com\/securitysnacks\/securitysnack-cloudflare-anti-security-for-phishing\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">According to the DomainTools report<\/a>, victims who passed all checks were redirected to the actual phishing URL \u2014 formatted as <code>https[:]\/\/office.suitetosecured[.]com\/KuPbXodA?b=cGjQKg4&amp;auth={}<\/code> \u2014 which mimicked a Microsoft 365 login page designed to capture credentials in real time.<\/p>\n<p>Researchers noted that all phishing sites identified in this campaign shared the same Cloudflare Turnstile sitekey: <code>0x4AAAAAACG6TJhrsuZdpjsN<\/code>.<\/p>\n<p>Because this key is a static identifier tied to a specific Cloudflare dashboard configuration, security teams may be able to pivot on it across platforms like <a href=\"https:\/\/gbhackers.com\/shoda-censys-internet\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Shodan, Censys,<\/a> and URLScan to proactively discover newly registered phishing infrastructure before it is deployed in active campaigns.<\/p>\n<p>All domains in the campaign were registered through Namecheap, hosted on Cloudflare\u2019s IP infrastructure, and shared nameservers pointing to <code>cloudflare.com<\/code>.<\/p>\n<h2 class=\"wp-block-heading\" id=\"indicators-of-compromise\"><strong>Indicators of Compromise<\/strong><\/h2>\n<ul class=\"wp-block-list\">\n<li>securedsnmail[.]com<\/li>\n<li>securedreach[.]com<\/li>\n<li>wirelessmailsent[.]com<\/li>\n<li>suitecorporate[.]com<\/li>\n<li>suitetosecured[.]com<\/li>\n<\/ul>\n<p>This campaign underscores the urgent need for service providers like Cloudflare to strengthen their Know Your Customer (KYC) processes and build mechanisms that prevent their defensive features from being weaponized against the broader security community.<\/p>\n<p>As attackers grow more sophisticated in their abuse of legitimate platforms, proactive platform accountability becomes just as critical as endpoint defenses.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 94%,rgb(169,184,195) 100%)\"><strong>Follow us on <a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>, <a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>, and <a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a> for daily cybersecurity updates. <a href=\"https:\/\/cybersecuritynews.com\/contact-us\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Contact us<\/a> to feature your stories.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/cloudflare-anti-bot-features-microsoft-365\/\">Hackers Leveraging Cloudflare Anti-Bot Features to Steal Microsoft 365 Credentials<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Guru Baran<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/cloudflare-anti-bot-features-microsoft-365\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Hackers Leveraging Cloudflare Anti-Bot Features to Steal Microsoft 365 Credentials A sophisticated Microsoft 365 credential harvesting campaign that weaponizes Cloudflare\u2019s own protective features to evade detection and silently steal user login data. The campaign demonstrates a growing and troubling trend: threat actors turning the very tools designed to defend websites into shields for malicious infrastructure. [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63],"tags":[130],"class_list":["post-11294","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/11294"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=11294"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/11294\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=11294"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=11294"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=11294"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}