Sicurezza cloud · Furto di credenziali
Adversary-in-the-middle (AiTM) phishing usa domini typosquatted per rubare credenziali della AWS Console. Gli operatori hanno usato le credenziali intercettate per accedere ad almeno un account entro 20 minuti da indirizzi Mullvad VPN.
2 fonti · 10 mar
Help Net Security
Attackers use AiTM phishing kit, typosquatted domains to hijack AWS accounts - Help Net Security
AWS accounts holders are targeted with fake security alerts and redirected to a clone of the AWS Management Console sign-in page.
originaleDatadog Security Labs
Behind the console: Active phishing campaign targeting AWS console credentials | Datadog Security Labs
Datadog Security Research identified an active adversary-in-the-middle (AiTM) phishing campaign targeting AWS Console credentials via typosquatted domains that mimic AWS infrastructure.
originalePart of the PlainSec briefing for 2026-03-09
Every edition of this story: Campagna di phishing typosquatted ruba credenziali AWS Console