The “WorkMail Pivot”: Hackers Abuse AWS WorkMail to Bypass SES Sandbox
ID: 3515216d-257e-5a01-b905-bebc5ae350d6
STIX ID: report--3515216d-257e-5a01-b905-bebc5ae350d6
Feed Name: securityonline.info
Rapid7’s MDR investigation reveals attackers using leaked AWS credentials to bypass Amazon SES sandbox restrictions by provisioning victim-owned AWS WorkMail mailboxes and sending phishing/spam directly via WorkMail’s SMTP endpoint; this approach leverages legitimate infrastructure and creates CloudTrail blind spots, enabling immediate, higher-volume external email delivery. Rapid7 recommends preventive guardrails like blocking unused WorkMail with Service Control Policies and monitoring new organization creation and domain verification to detect and disrupt the pivot.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
