Attack trend alert: AWS-themed credential phishing technique
ID: 80f005b3-364f-52a1-adf7-c7a07c56e25b
STIX ID: report--80f005b3-364f-52a1-adf7-c7a07c56e25b
Feed Name: Expel Blog
Threat Score
Expel discovered and analyzed an AWS-themed credential phishing email that cloned the AWS sign-in page to harvest credentials. The report walks through their triage process using automated detections (Ruxie™), manual analysis with browser developer tools to observe POST requests storing credentials, and provides guidance for remediation (reset credentials, rotate keys, enable MFA, audit CloudTrail).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
