3 comments
Red teamer here. We've been doing this for a long time for all kinds of evasion. Storing payloads in Azure blob storage, for example, is an amazingly effective way to deliver malware through network filtering controls.<p>You can look at more of the capabilities we like to use at the LOTS project: <a href="https://lots-project.com/" rel="nofollow">https://lots-project.com/</a>
Their pie chart almost looks like part of my local DNS configuration. I have not yet blocked github.io or azure however. I built this Unbound DNS configuration file from all the AI submissions in the event I accidentally click on one before noticing the domain.<p><pre><code> local-zone: "workers.dev." always_null
local-zone: "pages.dev." always_null
local-zone: "vercel.app." always_null
local-zone: "netlify.app." always_null
local-zone: "dweb.link." always_null
local-zone: "ipfs.io." always_null
dig +short test.vercel.app
0.0.0.0</code></pre>
I bet they have an easier time getting past your blacklist filters than non-phishers.