JavaGhost’s Persistent Phishing Attacks From the Cloud
ID: 02aa9c1b-9f4f-5882-b9ab-bf6322091cdd
STIX ID: report--02aa9c1b-9f4f-5882-b9ab-bf6322091cdd
Feed Name: Palo Alto Networks Unit 42
### Executive Summary Unit 42 attributes a series of cloud-based phishing campaigns to the JavaGhost group, which leverages exposed long-term AWS credentials to create SES/WorkMail identities, generate temporary console access via STS (GetFederationToken/GetSigninToken), and establish persistence (admin IAM users/roles and signature security groups) while using evasion techniques to avoid CloudTrail detection; the report includes IoCs, detection queries, and mitigation recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
