news.mlab.sh
Back to the feed
phishing

“Legitimate” phishing: how attackers weaponize Amazon SES to bypass email security

High
Image: Securelist
Summary

This Securelist article details a concerning trend of attackers leveraging Amazon Simple Email Service (Amazon SES) for phishing campaigns. Attackers exploit legitimate access keys to send convincing emails that bypass standard email security measures due to the use of SPF, DKIM, and DMARC authentication. The tactic involves masking phishing URLs and utilizing custom HTML templates, making the emails appear entirely legitimate and avoiding typical blocklist restrictions. The rise of this technique is linked to compromised AWS credentials and the impersonation of service providers for sophisticated Business Email Compromise (BEC) attacks.

Read the full article at Securelist

Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data

Report an error
Confirmed errors are fixed and listed on /corrections.