Emerging phishing campaign targeting AWS accounts
ID: 8d1c63d0-54af-50d9-873a-b473f991cf9f
STIX ID: report--8d1c63d0-54af-50d9-873a-b473f991cf9f
Feed Name: Wiz Blog
This report recounts a phishing incident where an employee received an email containing an image that redirected to a PDF and ultimately to a cloned AWS sign-in page (hosted on attacker-controlled domains and using AWS SES and CloudFront). The phishing site mimicked the legitimate AWS login URL and attempted credential harvesting; the actor used link shorteners and third-party hosting, and several related suspicious domains and IPs were identified. The page was taken down before further investigation could confirm intent or compromise. The report lists IOCs and recommends defensive measures for AWS environments including disabling root logins with SCPs, using FIDO keys for Org Management accounts, shifting to SSO, enforcing least privilege, and enabling CloudTrail logging.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
