Threat actors are continuing to prioritize credential theft while using defensive and trusted services to evade detection. DomainTools reported a Microsoft 365 phishing operation that weaponizes Cloudflare protections (including Turnstile human verification) to block automated analysis and security crawlers, then selectively serves a credential-harvesting flow only to “clean” visitors. The infrastructure used additional gatekeeping such as IP reputation checks (including lookups via api.ipify.org), hardcoded blocks for security-vendor and cloud-provider ranges, and user-agent filtering that returns a fake 404 page to bots, with the theft logic hidden behind heavy obfuscation.
Separately, Hunt.io documented Operation Roundish, assessed with medium-high confidence as aligned to APT28 (Fancy Bear), after discovering an exposed open directory hosting a Roundcube exploitation toolkit used against Ukrainian targets (including mail.dmsu.gov.ua). The toolkit included XSS payloads, a Flask-based C2, and modules for credential harvesting, mail forwarding persistence, bulk email exfiltration, address book theft, and 2FA secret extraction, plus a Go-based Linux implant (httd) found on a compromised Ukrainian web application. In parallel reporting on credential-access tradecraft, Flashpoint analysis highlighted the low-cost DarkCloud infostealer (sold for about $30) that steals browser logins/cookies and other data and exfiltrates via common channels (email/FTP/Telegram/HTTP), while Aryaka Threat Labs described the BlackSanta campaign using steganographic lures and BYOVD techniques to disable EDR and enable stealthy data theft over HTTPS—underscoring that credential access and defense evasion remain common precursors to broader enterprise compromise.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
7 events from the most recent confirmed update back to the earliest known activity.
Cofense reported phishing campaigns that fingerprint victims using browser user-agent and related telemetry, then deliver platform-specific payloads, credential theft pages, or spoofed download screens tailored to the victim’s device and operating system. Examples included FleetDeck delivered to macOS users and Tiflux RAT to Windows users, with some campaigns also using Cloudflare-based user-agent blocking to evade analysis.
Push Security reported a phishing campaign targeting TikTok for Business users with Cloudflare-hosted pages, Google Storage redirects, and Cloudflare Turnstile checks to evade analysis. The operation uses reverse-proxy phishing pages to steal credentials and session cookies, enabling account hijacking even when two-factor authentication is enabled, with attacker domains registered on 2026-03-24.
DomainTools reported a Microsoft 365 credential-harvesting campaign that used Cloudflare Turnstile, IP filtering, and user-agent checks to block bots and researchers before serving phishing pages to real users. The campaign hid credential theft logic in an obfuscated custom virtual machine and could be tracked via a shared Turnstile sitekey.
In January 2026, researchers found an open directory on 203.161.50[.]145:8889 containing a full Roundcube exploitation toolkit, operator artifacts, a Flask-based C2, a CSS-injection side-channel server, and a Go-based Linux implant. The server also contained exfiltrated data from blog.pentagonteam[.]com, including source code and secrets.
The Roundish toolkit was used against mail.dmsu.gov.ua, the webmail system of Ukraine's State Migration Service, to steal credentials, exfiltrate mail and contacts, extract 2FA secrets, and establish persistence through Sieve mail-forwarding rules. Researchers assessed the activity with medium-high confidence as aligned with APT28 based on overlaps with Operation RoundPress.
Aryaka Threat Labs reported that the BlackSanta campaign has been active for about a year, using resume-themed ISO files in recruiting channels to deliver malware. The intrusion chain culminates in a BYOVD-based payload that disables AV/EDR, Microsoft Defender protections, and system logging to support stealthy theft.
Flashpoint reported that the low-cost DarkCloud infostealer has been circulating since 2022, sold for about $30 through Telegram and public storefronts. The malware steals browser credentials, cookies, financial data, and email-application details, lowering the barrier for credential theft.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
6 references tracked. Mallory keeps watching after this page renders.
darkreading.com
Open sourcebleepingcomputer.com
Open sourcecybersecuritynews.com
Open sourcehunt.io
Open sourcescworld.com
Open sourcedarkreading.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.