Threat actors are continuing to find new legitimate services to use as the first step in phishing campaigns, with app.conceptboard.com now being observed in the latest wave of Living off Legitimate Services (LoLS) phishing activity.
A recent campaign observed targeting Downer Group used a link hosted through the legitimate Conceptboard platform as the initial stage of the phishing attack.


Conceptboard is a legitimate online collaboration and digital whiteboard service similar to miro. Its app.conceptboard.com platform provides access to the company’s web application and login functionality.
The abuse of services such as this is becoming increasingly common because the initial URL doesn’t necessarily have the characteristics traditionally associated with a phishing domain.
Legitimate service first, phishing infrastructure second
The observed campaign follows a familiar pattern.
The victim receives an email containing a link to a legitimate Conceptboard URL. Because the initial domain belongs to a genuine and established online service, it may not immediately trigger the same reputation-based controls that a newly registered phishing domain would.
The victim is then taken through the campaign infrastructure until they ultimately reach the phishing page.
In this particular campaign, the final phishing page was hosted using the standard workers.dev infrastructure, putting the attack into a now-familiar chain:
Email → Conceptboard → phishing infrastructure → credential harvesting
This distinction is important.

Blocking workers.dev may identify or stop the final stage, but the initial Conceptboard URL is what makes the campaign more difficult to identify using traditional reputation-based email controls.
Why Conceptboard?
This is essentially the same security problem seen with other legitimate services being abused for phishing.
The attacker doesn’t need to convince an email security product that their own domain is trustworthy.
Instead, they can use a trusted third-party service to deliver the first part of the attack.
This is the essence of Living off Legitimate Services.
The legitimate service provides the reputation.
The attacker provides the malicious destination.
Conceptboard itself is not inherently malicious, and there is no suggestion that Conceptboard is responsible for the campaign. The issue is the abuse of a legitimate platform by threat actors.
Conceptboard’s own documentation confirms that app.conceptboard.com is its publicly available SaaS application and is used for legitimate account and board access.
workers.dev continues to appear behind the attacks
The use of Cloudflare’s workers.dev infrastructure is also noteworthy.
Cloudflare provides workers.dev subdomains to allow developers to deploy Cloudflare Workers without first configuring their own domain. The URLs follow a structure such as:
<worker-name>.<subdomain>.workers.dev
Cloudflare describes these as publicly accessible Worker URLs intended primarily for getting started, personal projects and similar use cases.
That makes the infrastructure attractive to attackers.
They can deploy web applications without having to acquire and configure a traditional domain, while benefiting from infrastructure belonging to a major cloud provider.
This does not mean that workers.dev is malicious. It is a legitimate Cloudflare service and is used extensively for legitimate development and production workloads. However if your company does not need to allow workers.dev then I would recommend blocking it.
The security challenge is distinguishing legitimate use from malicious use.
The bigger problem with LoLS
This campaign is another example of why simply looking at the domain in a phishing email is becoming less effective.
A security team might see:
app.conceptboard.com
and conclude that the URL belongs to a legitimate service.
That assessment is technically correct — but it doesn’t answer the more important question:
Why is this legitimate service appearing in this particular email, to this particular user, with this particular link?
That is where modern phishing detection needs to move beyond simple domain reputation.
Recent phishing activity observed across New Zealand and Australia has already shown increasing use of trusted services as the first stage of phishing campaigns, followed by secondary infrastructure where the actual attack takes place.
What should organisations do?
Organisations should consider adding legitimate services being abused in LoLS campaigns to their phishing investigation and hunting processes.
For this particular campaign, security teams should consider:
- looking for
app.conceptboard.comURLs arriving through email - looking for subsequent connections to
workers.dev - if possible for your organisation proactively block
workers.devandapp.conceptboard.com