logo

AWS SNS Abuse: Data Exfiltration and Phishing

ID: f0d31c1e-f444-5e7d-9d6f-c6b7f82960df

STIX ID: report--f0d31c1e-f444-5e7d-9d6f-c6b7f82960df

Feed Name: Elastic Security Labs

Date Published: 2025-03-13

Date Updated: 2026-04-27

...
...

Research detailing how adversaries can abuse AWS SNS for data exfiltration and smishing/phishing, including a whitebox-tested workflow (topic creation, email subscription, and message publishing), operational constraints (IAM roles, sandbox limits, sender IDs), and defensive best practices. It provides Elastic-focused CloudTrail detections and ES|QL hunting queries to flag rare SNS topic creation, email-based subscriptions, unusual Publish actions from EC2-assumed roles, and spikes in direct phone messaging, while noting logging gaps and recommending IAM hardening, enhanced logging, and anomaly monitoring.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.