logo

Tales from the cloud trenches: Using AWS CloudTrail to identify malicious activity and spot phishing campaigns

ID: 475e9036-adf9-556d-9143-7b3744683753

STIX ID: report--475e9036-adf9-556d-9143-7b3744683753

Feed Name: Datadog Security Labs

Threat Score
60/100

Date Published: 2024-03-15

Date Updated: 2026-04-27

...
...

Datadog Security Labs observed an active campaign in which attackers used compromised long-term AWS SNS credentials (AKIA...) to enumerate SMS capabilities across regions (GetSMSAttributes/GetSMSSandboxAccountStatus) and attempted to send phishing links via SMS; the same infrastructure hosted French government impersonation phishing kits that collected PII and credit card data and sent it to attacker-controlled Telegram channels, with multiple domains, IPs, and phishing-kit SHA256s identified and provided as IOCs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.