Researchers report Amazon SES abused in phishing to evade detection
ID: 5aca9747-b91e-5177-bc7b-66221d1a979d
STIX ID: report--5aca9747-b91e-5177-bc7b-66221d1a979d
Feed Name: Bleeping Computer
Kaspersky has observed an uptick in phishing and BEC campaigns that abuse Amazon SES by using exposed AWS IAM access keys discovered in public repositories and assets; because SES is a trusted email-sending service, attackers can send authenticated, realistic phishing emails and host phishing pages on AWS, evading SPF/DKIM/DMARC and reputation-based defenses. The report describes automated secret-scanning (e.g., TruffleHog), examples like fake DocuSign notifications and fraudulent invoices, and recommends least-privilege IAM, MFA, key rotation, IP restrictions, and reporting abusive activity to AWS.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
