Researchers uncovered two large-scale malicious infrastructures that used Cloudflare-fronted domains and wildcard subdomains to hide centralized backend systems. In one campaign, investigators traced an adversary-in-the-middle (AiTM) phishing operation from four suspicious domains to at least seven domains and more than 200 subdomains impersonating enterprise VPN and SSO portals, including Palo Alto GlobalProtect, Fortinet FortiGate, Cisco AnyConnect, Citrix, and Microsoft OWA. The phishing flow presented fake Cloudflare challenge pages before credential prompts, and the infrastructure was linked to a single origin server at 178.16.53.131 in Germany. Researchers said the platform could relay live authentication sessions and steal both credentials and session tokens, allowing attackers to bypass traditional MFA protections.
A separate investigation tied a single ClearFake indicator to a broader malware delivery network spanning 24 .in.net domains, more than 100 subdomains, two Cloudflare account clusters, and a shared WebDAV origin server. Analysts found wildcard DNS and TLS certificates across the domains, identical ETag values indicating common hosting, and an exposed payload inventory accessible through unauthenticated WebDAV requests. The campaign used compromised websites to redirect victims to fake verification pages and then delivered malicious DLLs and two newly identified obfuscated Go binaries disguised as Logitech and Intel components. Breakglass reported that the recovered payloads had zero detections in VirusTotal and MalwareBazaar at the time of discovery, while multiple OPSEC mistakes—including leaked headers, an exposed staging directory, and a recurring "werification" typo—helped map the operation.

Get the infrastructure and lures behind it.
2 events from the most recent confirmed update back to the earliest known activity.
Researchers identified a professionally operated adversary-in-the-middle phishing platform using Cloudflare-fronted domains that impersonated enterprise VPN and SSO login pages. Their investigation expanded from four initially flagged domains to at least seven confirmed domains and more than 200 subdomains tied to a single origin server in Dusseldorf, Germany.
Breakglass Intelligence analyzed a ThreatFox ClearFake indicator and identified a broader malware delivery network using 24 .in.net domains, more than 100 subdomains, Cloudflare-fronted WebDAV infrastructure, and three previously unseen payload files. The recovered payloads had no detections in VirusTotal or MalwareBazaar at the time of analysis, and abuse reports were filed with Cloudflare and PDR Ltd.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 36 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
2 references tracked. Mallory keeps watching after this page renders.
intel.breakglass.tech
Open sourceintel.breakglass.tech
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.