Cloud · 203 giorni fa
Datadog observed an active adversary-in-the-middle phishing campaign that proxied AWS sign-in pages to capture validated Console credentials and OTPs. Operators used captured material to access at least one account within 20 minutes from Mullvad VPN IPs. Block the typosquatted domains, enforce
2 fonti che coprono questa storia
Attackers use AiTM phishing kit, typosquatted domains to hijack AWS accounts - Help Net Security
AWS accounts holders are targeted with fake security alerts and redirected to a clone of the AWS Management Console sign-in page.
Datadog Security Research identified an active adversary-in-the-middle (AiTM) phishing campaign targeting AWS Console credentials via typosquatted domains that mimic AWS infrastructure.
Part of the PlainSec briefing for 2026-03-15