Cloud-Native Phishing Infrastructure via Abused AWS WorkMail (Campaign)
ID: f63c015c-71f8-5ce4-be6a-0447fa2139f1
STIX ID: report--f63c015c-71f8-5ce4-be6a-0447fa2139f1
Feed Name: Wiz Cloud Threat Landscape
Date Published: 2026-01-27
Date Updated: 2026-05-01
Author: [email protected] (Wiz Threat Research)
Threat actors abused exposed long-term AWS credentials to perform IAM reconnaissance, escalate privileges, and operationalize phishing by sending emails from victim-owned AWS WorkMail (after SES sandbox limits hindered large-scale use). By leveraging WorkMail's lighter controls and Amazon's sender reputation, attackers can cheaply and stealthily send external phishing with minimal centralized telemetry, creating detection blind spots and putting any organization with leaked credentials and permissive IAM policies at risk.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
