Attackers use AiTM phishing kit, typosquatted domains to hijack AWS accounts
ID: 15291f2d-097d-5e09-a4c5-7644d0d4f1c8
STIX ID: report--15291f2d-097d-5e09-a4c5-7644d0d4f1c8
Feed Name: Help Net Security
Phishers are running an adversary-in-the-middle (AiTM) phishing campaign impersonating AWS security alerts that relay real authentication to capture credentials, MFA codes, and session tokens via high-fidelity AWS Management Console clones hosted on typosquatted domains. Datadog observed active exploitation — an attacker authenticated to a compromised console within about 20 minutes from IP 185.209.196.132 — and identified a shared phishing kit also configured for Microsoft 365 and Apple impersonation, with rapidly rotated domains to evade takedown.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
