< Back to all clusters
[TECHNOLOGY] · 2 sources

started · updated

Cybersecurity researchers identify new AWS phishing campaign

Security researchers have identified a new phishing campaign targeting Amazon Web Services (AWS) credentials. The Wiz Threat Research Team discovered that attackers are using phishing emails containing PNG images to redirect victims through a series of links, including a PDF viewer and an attacker-controlled domain, to a final credential harvesting page. The campaign utilizes Amazon SES to send emails, indicating the use of AWS accounts to facilitate the attack.

In separate cybersecurity developments, identity intelligence tools are being used to trace complex criminal networks. In one instance, investigators used email fragments to link a government phishing attack to a Telegram account involved in the sale of phishing kits and exploits. In another case, organized retail crime teams and Homeland Security Investigations utilized shared identifiers, such as phone numbers and email addresses, to dismantle a sophisticated markdown fraud scheme involving high-end electronics and fraudulent price-match claims.

Entities

Amazon Web Services · Fideo Intelligence · Google Chrome · Homeland Security Investigations · Wiz