logo

Attackers use AiTM phishing kit, typosquatted domains to hijack AWS accounts

ID: 15291f2d-097d-5e09-a4c5-7644d0d4f1c8

STIX ID: report--15291f2d-097d-5e09-a4c5-7644d0d4f1c8

Feed Name: Help Net Security

Threat Score
70/100

Date Published: 2026-03-10

Date Updated: 2026-04-28

Author: Zeljka Zorz

...
...

Phishers are running an adversary-in-the-middle (AiTM) phishing campaign impersonating AWS security alerts that relay real authentication to capture credentials, MFA codes, and session tokens via high-fidelity AWS Management Console clones hosted on typosquatted domains. Datadog observed active exploitation — an attacker authenticated to a compromised console within about 20 minutes from IP 185.209.196.132 — and identified a shared phishing kit also configured for Microsoft 365 and Apple impersonation, with rapidly rotated domains to evade takedown.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.