AWS misconfigurations reportedly used to launch phishing attacks




  • Threat actors seen abusing AWS misconfigurations to gain access to the instances
  • They would use the instances to create new SES and WorkMail services
  • The emails would bypass email security, while keeping the attackers hidden

Misconfigured Amazon Web Services (AWS) environments are being abused to run phishing campaigns that can bypass email filters and land right into people’s inboxes, experts have claimed.

Cybersecurity researchers from Palo Alto Networks’ Unit 42 recently spotted a group tracked as TGR-UNK-0011 engaging in this type of attack.

https://cdn.mos.cms.futurecdn.net/4HQfMQ7ScfTqv5RDukfnYA-1200-80.jpg



Source link

Latest articles

spot_imgspot_img

Related articles

spot_imgspot_img