AWS Console Credentials Harvested; Accounts Accessed Within 20 Minutes

Datadog observed an active adversary-in-the-middle phishing campaign that proxied AWS sign-in pages to capture validated Console credentials and OTPs. Operators used captured material to access at least one account within 20 minutes from Mullvad VPN IPs. Block the typosquatted domains, enforce

Part of the PlainSec briefing for 2026-03-15

Sources