logo

Threat Actor 'JavaGhost' Targets AWS Environments in Phishing Scheme

ID: 948b24da-379f-5b85-8a89-2de3127a8f6b

STIX ID: report--948b24da-379f-5b85-8a89-2de3127a8f6b

Feed Name: Dark Reading

Threat Score
70/100

Date Published: 2025-03-04

Date Updated: 2026-04-21

Author: Alexander Culafi, Senior News Writer, Dark Reading

...
...

**JavaGhost cloud phishing campaign:** Unit 42 reports that JavaGhost has been exploiting exposed long‑term AWS IAM access keys and misconfigured environments since 2022 to establish persistent phishing infrastructure, using victim Amazon SES/WorkMail to send emails that evade detection; the group employs CloudTrail evasion techniques (avoiding GetCallerIdentity, creating temporary console credentials) and benefits from missing dataplane logging, while recommended mitigations include enabling dataplane logging and tightening IAM permissions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.