logo

Amazon SES increasingly abused in phishing to evade detection

ID: b4af3452-9dfe-5244-95f1-a4c1fc7ebe45

STIX ID: report--b4af3452-9dfe-5244-95f1-a4c1fc7ebe45

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2026-05-04

Date Updated: 2026-05-05

Author: Bill Toulas

...
...

Kaspersky researchers observed a rising campaign that abuses Amazon SES—using exposed AWS IAM access keys discovered in public repos and assets—to send high-quality phishing and BEC emails that bypass SPF/DKIM/DMARC and reputation-based blocks; attackers automate secret scanning, permission checks, and mass distribution (often hosting phishing pages on AWS). The report highlights attack techniques (fabricated threads, DocuSign-style lures, fake invoices), recommends least-privilege IAM, MFA, key rotation, IP restrictions and provides guidance for reporting abuse to AWS Trust & Safety.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.