logo

AWS Phishing Exploits

ID: a96da2df-2d95-51a7-b216-06ef05fd82fc

STIX ID: report--a96da2df-2d95-51a7-b216-06ef05fd82fc

Feed Name: Canary Trap

Threat Score
60/100

Date Published: 2025-03-10

Date Updated: 2026-05-13

Author: Canary Trap

...
...

JavaGhost (TGR-UNK-0011) leverages exposed AWS IAM keys and misconfigurations to provision SES and WorkMail services, create IAM users and roles (including long-lived and temporary credentials), and send phishing emails that appear to come from trusted sources; they also leave telltale but non-functional EC2 security groups named "Java_Ghost" that appear in CloudTrail as an identifying trace.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.