AWS AiTM Phishing Kit Steals Console Credentials and MFA Codes in Real Time
ID: 17ec63fa-3199-55e4-8690-95547db14041
STIX ID: report--17ec63fa-3199-55e4-8690-95547db14041
Feed Name: cybersecurityNews.com
Researchers from Datadog Security Labs uncovered a targeted AiTM phishing campaign (June 19–23, 2026) that used near-perfect clones of the AWS sign-in page and a server-driven JavaScript relay to capture credentials and multi-factor codes in real time, enabling attackers to hijack console sessions before victims could react; investigators found a small set of targeted engineering accounts, several phishing domains and SendGrid-impersonation domains, and published IoCs and defensive recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
