← RegistryDossier · 6 steps · 5 edges
Cloudflare account compromise → Worker rewrite → mass cred theft
Phish a Cloudflare account belonging to a popular site operator. Deploy a Worker that injects JS into every response — captures form posts (logins, payments) for the duration the operator doesn't notice.
Filed by AD Knowledge Base
§ Kill-chainDrag · zoom · scroll
§ Context
Assumed environment: target operates a high-traffic site fronted by Cloudflare. Cloudflare account has no hardware-key MFA / API token has Worker scope.
§ Steps
- 01Pipe to attacker-controlled endpointExfiltrationT1041— Exfiltration Over C2 Channel
- 02Remove Worker before detectionDefense EvasionT1070— Indicator Removal
- 03Worker injects JS into responsesImpactW-XSS-STORED— Stored XSS
- 04Phish Cloudflare admin credential / tokenInitial AccessPH-AITM-EVILGINX— AITM Phishing — Evilginx / Modlishka
- 05Capture form posts (logins, payments)CollectionT1056— Input Capture
- 06Deploy attacker Cloudflare WorkerInitial AccessCDN-WORKER-COMPROMISE— Cloudflare Worker / Edge Function Compromise
§ References
- T1041Exfiltration Over C2 Channel
- T1070Indicator Removal
- T1056Input Capture
§ Frequently asked
- What is the "Cloudflare account compromise → Worker rewrite → mass cred theft" attack path?
- Phish a Cloudflare account belonging to a popular site operator. Deploy a Worker that injects JS into every response — captures form posts (logins, payments) for the duration the operator doesn't notice. It chains 6 steps drawn from real-world offensive-security techniques.
- What starting position does this attack require?
- The first step is Pipe to attacker-controlled endpoint (T1041) — a exfiltration primitive. Assumed environment: target operates a high-traffic site fronted by Cloudflare.
- What is the final impact of this kill-chain?
- The final step lands on Deploy attacker Cloudflare Worker (CDN-WORKER-COMPROMISE), which falls under Initial Access. From here, an operator typically pivots into post-exploitation or maintains persistence.
- How can defenders detect or prevent this attack?
- Detection and prevention vary per step. Refer to each linked MITRE ATT&CK entry under "References" — every technique on that page lists defensive controls, detection telemetry, and known threat-actor usage.
§ Related dossiers
- Shared techniques2
Mass SMS phish → Okta-style portal → SaaS sprawl (0ktapus)
Wide SMS phishing campaign targeting employees of ~130 organisations with a single phishlet that captures Okta credentials + push approval. Mass automated logins to Twilio, MailChimp, DoorDash et al.
- Shared techniques2
MITM unencrypted RTP → call eavesdropping
Most internal SIP deployments still use RTP without SRTP. From the same VLAN, ARP-spoof the IP phone + PBX, capture RTP, decode in Wireshark to .wav.