Attackers have started using another legitimate service for malicious purposes.

Experts from Kaspersky Lab have identified a new phishing attack technique targeting the corporate sector, which involves a legitimate AI platform. Attackers are using the Tencent EdgeOne Pages service, designed for rapid web development, to create and host fraudulent websites.

The attack begins with emails disguised as official notifications from corporate email support. The message warns the user about the imminent expiration of their credentials and offers to "renew" them by clicking on a link. Over the past month, more than 8,000 such emails have been detected, including those in Russian.

The peculiarity of the scheme is the speed and simplicity of infrastructure creation. The Tencent EdgeOne Pages platform allows fraudsters to generate phishing pages in seconds and host them in a trusted cloud environment using legitimate domains. This makes malicious websites appear similar to safe, long-standing resources, which significantly complicates their automatic detection. Cybersecurity expert Roman Dedenok explained:

If previously this required at least basic web development skills, now the infrastructure for fraudulent mailings can be organized in minutes.