Tales from the cloud trenches: Using AWS CloudTrail to identify malicious activity and spot phishing campaigns
ID: 475e9036-adf9-556d-9143-7b3744683753
STIX ID: report--475e9036-adf9-556d-9143-7b3744683753
Feed Name: Datadog Security Labs
Datadog Security Labs observed an active campaign in which attackers used compromised long-term AWS SNS credentials (AKIA...) to enumerate SMS capabilities across regions (GetSMSAttributes/GetSMSSandboxAccountStatus) and attempted to send phishing links via SMS; the same infrastructure hosted French government impersonation phishing kits that collected PII and credit card data and sent it to attacker-controlled Telegram channels, with multiple domains, IPs, and phishing-kit SHA256s identified and provided as IOCs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
