Threat Actor 'JavaGhost' Targets AWS Environments in Phishing Scheme
ID: 948b24da-379f-5b85-8a89-2de3127a8f6b
STIX ID: report--948b24da-379f-5b85-8a89-2de3127a8f6b
Feed Name: Dark Reading
Date Published: 2025-03-04
Date Updated: 2026-04-21
Author: Alexander Culafi, Senior News Writer, Dark Reading
**JavaGhost cloud phishing campaign:** Unit 42 reports that JavaGhost has been exploiting exposed long‑term AWS IAM access keys and misconfigured environments since 2022 to establish persistent phishing infrastructure, using victim Amazon SES/WorkMail to send emails that evade detection; the group employs CloudTrail evasion techniques (avoiding GetCallerIdentity, creating temporary console credentials) and benefits from missing dataplane logging, while recommended mitigations include enabling dataplane logging and tightening IAM permissions.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
