logo

TruffleNet Campaign Exploits AWS SES for Large-Scale Cloud Abuse and BEC Fraud (Campaign)

ID: 517eb93c-b58d-592f-94af-a6d87bcafdd4

STIX ID: report--517eb93c-b58d-592f-94af-a6d87bcafdd4

Feed Name: Wiz Cloud Threat Landscape

Threat Score
75/100

Date Published: 2025-10-31

Date Updated: 2026-05-01

Author: [email protected] (Wiz Threat Research)

...
...

Researchers uncovered a large-scale criminal campaign that automated validation of stolen AWS credentials using a custom infrastructure named TruffleNet and abused Amazon SES to create verified sender identities for Business Email Compromise (BEC). The adversaries used AWS CLI/Boto3 calls (e.g., GetCallerIdentity, GetSendQuota), Portainer for orchestration, and stolen DKIM keys from compromised WordPress sites to send authenticated phishing and financial fraud at scale, with follow-on privilege escalation attempts.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.