logo

JavaGhost’s Persistent Phishing Attacks From the Cloud

ID: 02aa9c1b-9f4f-5882-b9ab-bf6322091cdd

STIX ID: report--02aa9c1b-9f4f-5882-b9ab-bf6322091cdd

Feed Name: Palo Alto Networks Unit 42

Threat Score
75/100

Date Published: 2025-02-28

Date Updated: 2026-04-28

Author: Margaret Kelley

...
...

### Executive Summary Unit 42 attributes a series of cloud-based phishing campaigns to the JavaGhost group, which leverages exposed long-term AWS credentials to create SES/WorkMail identities, generate temporary console access via STS (GetFederationToken/GetSigninToken), and establish persistence (admin IAM users/roles and signature security groups) while using evasion techniques to avoid CloudTrail detection; the report includes IoCs, detection queries, and mitigation recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.