logo

AWS AiTM Phishing Kit Steals Console Credentials and MFA Codes in Real Time

ID: 17ec63fa-3199-55e4-8690-95547db14041

STIX ID: report--17ec63fa-3199-55e4-8690-95547db14041

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2026-06-25

Date Updated: 2026-06-25

Author: Tushar Subhra Dutta

...
...

Researchers from Datadog Security Labs uncovered a targeted AiTM phishing campaign (June 19–23, 2026) that used near-perfect clones of the AWS sign-in page and a server-driven JavaScript relay to capture credentials and multi-factor codes in real time, enabling attackers to hijack console sessions before victims could react; investigators found a small set of targeted engineering accounts, several phishing domains and SendGrid-impersonation domains, and published IoCs and defensive recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.