logo

The “WorkMail Pivot”: Hackers Abuse AWS WorkMail to Bypass SES Sandbox

ID: 3515216d-257e-5a01-b905-bebc5ae350d6

STIX ID: report--3515216d-257e-5a01-b905-bebc5ae350d6

Feed Name: securityonline.info

Threat Score
65/100

Date Published: 2026-01-30

Date Updated: 2026-04-23

Author: Ddos

...
...

Rapid7’s MDR investigation reveals attackers using leaked AWS credentials to bypass Amazon SES sandbox restrictions by provisioning victim-owned AWS WorkMail mailboxes and sending phishing/spam directly via WorkMail’s SMTP endpoint; this approach leverages legitimate infrastructure and creates CloudTrail blind spots, enabling immediate, higher-volume external email delivery. Rapid7 recommends preventive guardrails like blocking unused WorkMail with Service Control Policies and monitoring new organization creation and domain verification to detect and disrupt the pivot.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.