logo

Hackers Abuse Cloudflare-Hosted AWS Phishing Domains to Steal Console Logins

ID: 9ea450a9-0f0a-5cd2-9316-d07a93c2b4df

STIX ID: report--9ea450a9-0f0a-5cd2-9316-d07a93c2b4df

Feed Name: GBHackers

Threat Score
78/100

Date Published: 2026-06-25

Date Updated: 2026-06-25

Author: Mayura Kathir

...
...

Datadog observed a targeted phishing campaign (June 16–19, 2026) that cloned the AWS console on Cloudflare-hosted domains and used a server-driven AiTM phishing kit to capture credentials and second-factor authentication (email, SMS, or authenticator) in real time. The kit used an encrypted input_24 gating parameter and API-based flows to selectively render pages and relay authentication attempts to legitimate AWS endpoints, enabling immediate MFA code reuse. Operators registered multiple domains via NICENIC, leveraged SendGrid/Nimbu for delivery, and left observable domains and artifacts; defenders are advised to block/monitor the listed domains, hunt DNS and CloudTrail ConsoleLogin events, and encourage phishing-resistant FIDO2 and conditional access controls.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.