Hackers Abuse Cloudflare-Hosted AWS Phishing Domains to Steal Console Logins
ID: 9ea450a9-0f0a-5cd2-9316-d07a93c2b4df
STIX ID: report--9ea450a9-0f0a-5cd2-9316-d07a93c2b4df
Feed Name: GBHackers
Datadog observed a targeted phishing campaign (June 16–19, 2026) that cloned the AWS console on Cloudflare-hosted domains and used a server-driven AiTM phishing kit to capture credentials and second-factor authentication (email, SMS, or authenticator) in real time. The kit used an encrypted input_24 gating parameter and API-based flows to selectively render pages and relay authentication attempts to legitimate AWS endpoints, enabling immediate MFA code reuse. Operators registered multiple domains via NICENIC, leveraged SendGrid/Nimbu for delivery, and left observable domains and artifacts; defenders are advised to block/monitor the listed domains, hunt DNS and CloudTrail ConsoleLogin events, and encourage phishing-resistant FIDO2 and conditional access controls.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
