logo

JavaGhost SES abuse (Campaign)

ID: 7cf17db2-a2ef-567b-90e6-f3ce780eb4c7

STIX ID: report--7cf17db2-a2ef-567b-90e6-f3ce780eb4c7

Feed Name: Wiz Cloud Threat Landscape

Threat Score
75/100

Date Published: 2025-02-28

Date Updated: 2026-05-01

Author: [email protected] (Wiz Threat Research)

...
...

JavaGhost evolved from defacements to sustained cloud phishing (2022–2024) by exploiting exposed long-term AWS access keys to access SES and WorkMail and send phishing from trusted infrastructure; they used IAM manipulation (creating users/roles with admin privileges), temporary credential APIs (GetFederationToken, GetSigninToken) and urllib3 to generate console sign-in URLs, established cross-account trust for persistence, and employed evasion techniques such as avoiding GetCallerIdentity and leaving subtle artifacts (e.g., empty EC2 security groups named "Java_Ghost").

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.