logo

AWS Login Phishing Attack: How Attackers Exploit New Authentication

ID: 217b894b-47db-53ad-9f80-5158167b4acd

STIX ID: report--217b894b-47db-53ad-9f80-5158167b4acd

Feed Name: Mitiga

Threat Score
78/100

Date Published: 2026-07-22

Date Updated: 2026-07-29

...
...

This report documents a proof-of-concept AWS-hosted phishing campaign that abuses the new 'aws login --remote' cross-device authentication flow: attackers host a convincing phishing page on amazonaws.com (S3) and orchestrate AWS services (Lambda, DynamoDB, API Gateway, EC2) to generate per-visitor device-code URLs, collect Base64 JWT verification codes from victims, and complete CLI logins on attacker infrastructure. The paper details the attack flow, persistence risks (creating IAM users/keys, role assumptions), detection signals in CloudTrail (AuthorizeOAuth2Access/CreateOAuth2Token with requestParameters.client_id = arn:aws:signin:::devtools/cross-device and IP/user-agent mismatches), and a mitigation: use Service Control Policies to deny the signin:AuthorizeOAuth2Access and signin:CreateOAuth2Token actions where cross-device sign-in is not required.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.