Phishing at Cloud Scale: How AWS is Abused for Credential Theft
ID: 505aeb4c-9697-5084-b8fa-f19e0463fa20
STIX ID: report--505aeb4c-9697-5084-b8fa-f19e0463fa20
Feed Name: Cofense Blog
Threat Score
This report analyzes how threat actors exploit AWS services—notably S3 buckets, SES (awstrack.me tracking links), and Amplify—to host and disseminate large-scale credential-phishing campaigns, outlines observed TTPs and example phishing pages from 2021–2025, highlights the abuse of trusted AWS infrastructure to evade email security controls, and summarizes AWS and vendor mitigation recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
