“Legitimate” phishing: how attackers weaponize Amazon SES to bypass email security
This Securelist article details a concerning trend of attackers leveraging Amazon Simple Email Service (Amazon SES) for phishing campaigns. Attackers exploit legitimate access keys to send convincing emails that bypass standard email security measures due to the use of SPF, DKIM, and DMARC authentication. The tactic involves masking phishing URLs and utilizing custom HTML templates, making the emails appear entirely legitimate and avoiding typical blocklist restrictions. The rise of this technique is linked to compromised AWS credentials and the impersonation of service providers for sophisticated Business Email Compromise (BEC) attacks.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data
