AWS SNS Abuse: Data Exfiltration and Phishing
ID: f0d31c1e-f444-5e7d-9d6f-c6b7f82960df
STIX ID: report--f0d31c1e-f444-5e7d-9d6f-c6b7f82960df
Feed Name: Elastic Security Labs
Research detailing how adversaries can abuse AWS SNS for data exfiltration and smishing/phishing, including a whitebox-tested workflow (topic creation, email subscription, and message publishing), operational constraints (IAM roles, sandbox limits, sender IDs), and defensive best practices. It provides Elastic-focused CloudTrail detections and ES|QL hunting queries to flag rare SNS topic creation, email-based subscriptions, unusual Publish actions from EC2-assumed roles, and spikes in direct phone messaging, while noting logging gaps and recommending IAM hardening, enhanced logging, and anomaly monitoring.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
