Keep your eyes on these

VERY IMPORTANT

Security Articles

RSS

Behind the console: An AiTM phishing kit harvesting AWS console credentials and beyond

released on 2026-06-25 @ 03:26:35 PM
Between June 16 and 19, 2026, a sophisticated adversary-in-the-middle phishing campaign targeted AWS console users through three domains registered within 48 hours and hosted on Cloudflare. The campaign impersonated AWS login pages and captured credentials along with real-time multi-factor authentication codes through email, SMS, and authenticator apps. Phishing emails were delivered through legitimate platforms like SendGrid and Nimbu to bypass spam filters. The kit employed JavaScript-based credential harvesting with victim validation through encrypted URL parameters, preventing sandbox analysis. Targets were primarily US-based software engineers and engineering leadership, suggesting a curated target list rather than mass phishing. The same kit was linked to concurrent SendGrid impersonation campaigns and previous cryptocurrency wallet targeting since July 2025. The small sample of fewer than 50 targeted email addresses indicates highly selective targeting of technical personnel with AWS access.