AWS Console Alert: Real-Time “AiTM” Phishing Campaign Bypasses MFA with Rapid Precision
ID: 4a1abdd0-9e10-5f09-b6c0-146c30d3d724
STIX ID: report--4a1abdd0-9e10-5f09-b6c0-146c30d3d724
Feed Name: securityonline.info
Datadog Security Research identified an active AiTM phishing campaign that clones the AWS Management Console and proxies authentication to capture credentials and MFA codes in real time, using typosquatted domains (e.g., cloud-recovery.net, cloud-policy.com) and legitimate CloudFront assets. The operation enables rapid account takeover (observed compromises within ~20 minutes); recommended mitigations include enforcing FIDO2/WebAuthn, monitoring egress to the listed domains, and navigating to the AWS Console via trusted bookmarks.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
