logo

AWS Console Alert: Real-Time “AiTM” Phishing Campaign Bypasses MFA with Rapid Precision

ID: 4a1abdd0-9e10-5f09-b6c0-146c30d3d724

STIX ID: report--4a1abdd0-9e10-5f09-b6c0-146c30d3d724

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2026-03-09

Date Updated: 2026-04-23

Author: Ddos

...
...

Datadog Security Research identified an active AiTM phishing campaign that clones the AWS Management Console and proxies authentication to capture credentials and MFA codes in real time, using typosquatted domains (e.g., cloud-recovery.net, cloud-policy.com) and legitimate CloudFront assets. The operation enables rapid account takeover (observed compromises within ~20 minutes); recommended mitigations include enforcing FIDO2/WebAuthn, monitoring egress to the listed domains, and navigating to the AWS Console via trusted bookmarks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.