logo

From Compromised Keys to Phishing Campaigns: Inside a Cloud Email Service Takeover

ID: 820079be-d968-5001-8427-e6c5d50eddb1

STIX ID: report--820079be-d968-5001-8427-e6c5d50eddb1

Feed Name: Wiz Blog

Threat Score
70/100

Date Published: 2025-09-04

Date Updated: 2026-05-01

...
...

Wiz Research describes a May 2025 Amazon SES abuse campaign in which attackers leveraged compromised AWS access keys to bypass SES sandbox restrictions (including novel multi-regional PutAccountDetails requests), verify attacker and weakly protected domains, create sender identities, and send credential-theft phishing at scale; the report provides IoCs (domains and sender prefixes), outlines attacker TTPs and novel indicators (e.g., API-based CreateCase usage, multi-region PutAccountDetails bursts), and offers detection and mitigation guidance for defenders.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.