logo

Attack trend alert: AWS-themed credential phishing technique

ID: 80f005b3-364f-52a1-adf7-c7a07c56e25b

STIX ID: report--80f005b3-364f-52a1-adf7-c7a07c56e25b

Feed Name: Expel Blog

Threat Score
35/100

Date Published: 2022-02-01

Date Updated: 2026-04-27

Author: Simon Wong; Emily Hudson

...
...

Expel discovered and analyzed an AWS-themed credential phishing email that cloned the AWS sign-in page to harvest credentials. The report walks through their triage process using automated detections (Ruxie™), manual analysis with browser developer tools to observe POST requests storing credentials, and provides guidance for remediation (reset credentials, rotate keys, enable MFA, audit CloudTrail).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.