TruffleNet Campaign Exploits AWS SES for Large-Scale Cloud Abuse and BEC Fraud (Campaign)
ID: 517eb93c-b58d-592f-94af-a6d87bcafdd4
STIX ID: report--517eb93c-b58d-592f-94af-a6d87bcafdd4
Feed Name: Wiz Cloud Threat Landscape
Date Published: 2025-10-31
Date Updated: 2026-05-01
Author: [email protected] (Wiz Threat Research)
Researchers uncovered a large-scale criminal campaign that automated validation of stolen AWS credentials using a custom infrastructure named TruffleNet and abused Amazon SES to create verified sender identities for Business Email Compromise (BEC). The adversaries used AWS CLI/Boto3 calls (e.g., GetCallerIdentity, GetSendQuota), Portainer for orchestration, and stolen DKIM keys from compromised WordPress sites to send authenticated phishing and financial fraud at scale, with follow-on privilege escalation attempts.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
