Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
AWS Phishing Kit Exploits MFA for Real-Time Access

AWS Phishing Kit Exploits MFA for Real-Time Access

Posted on June 25, 2026 By CWS

A sophisticated phishing kit has emerged, targeting Amazon Web Services (AWS) users by capturing login credentials and multi-factor authentication (MFA) codes in real-time. This advancement allows attackers to gain access to a victim’s AWS console before the victim notices any suspicious activity.

Innovative Attack Methodology

This phishing campaign, identified between June 19 and 23, 2026, represents a notable evolution in cloud account attacks. The kit employs an adversary-in-the-middle (AiTM) tactic, creating a stealthy relay between the victim and the legitimate AWS login page. As users enter their credentials and MFA codes, these are transmitted directly to the attacker, who then forwards them to the AWS servers. This process allows attackers to swiftly access the victim’s AWS session, rendering MFA protections ineffective.

Research and Findings

Datadog Security Labs uncovered the campaign and provided insights into its operations. The researchers identified three phishing domains, all registered within 24 hours through NICENIC INTERNATIONAL GROUP CO., LIMITED and hosted on Cloudflare. These domains expertly mimicked the AWS console login page, making it challenging for users to detect fraudulent activity.

The phishing emails, masquerading as AWS Support, were sent via trusted platforms such as SendGrid and Nimbu, bypassing email authentication filters. The emails fabricated a bandwidth throttling issue to prompt urgent user action, luring recipients to engage without scrutinizing the validity of the request.

Targeted Phishing Strategy

This campaign distinguished itself by not indiscriminately targeting users. The phishing kit only displayed the fake login page to pre-verified email addresses, with fewer than 50 targets identified, primarily software engineers and engineering leaders in the United States. This specificity suggests a highly targeted approach rather than a broad phishing scheme.

The kit’s core functionality resided in a single JavaScript file on the fraudulent AWS login page. This file read and verified encrypted values from the URL against the attacker’s server, ensuring that only intended targets saw the login form. This method also prevented security researchers from analyzing the page effectively.

Broader Implications and Defense Measures

Beyond AWS, researchers found additional domains impersonating SendGrid, sharing similar registration timelines and technical characteristics. This indicates a common threat actor refining their toolkit over time, affecting various industries.

To mitigate such threats, security teams are advised to monitor DNS queries for known phishing domains and scrutinize AWS CloudTrail logs for suspicious ConsoleLogin events. Identifying successful logins shortly after phishing domain contact could signal an attacker replaying a compromised session. Recognizing AWS console phishing as a critical threat is paramount to enhancing cybersecurity defenses.

Indicators of Compromise (IoCs) include several domains, such as us-west-login[.]com and aws-central.us-west-login[.]com, among others. These IoCs serve as crucial data points for threat intelligence and proactive defense strategies.

Cyber Security News Tags:Adversary-in-the-Middle, AWS, cloud accounts, cloud security, cyber attack, Cybersecurity, Datadog, email phishing, MFA, Nimbu, Phishing, real-time attack, Security, SendGrid, threat detection

Post navigation

Previous Post: Russia’s Use of Cellebrite to Access Activist’s iPhone

Related Posts

Conduent’s Massive Data Breach: 8 TB Stolen by Ransomware Conduent’s Massive Data Breach: 8 TB Stolen by Ransomware Cyber Security News
Microsoft Introduces Researcher in Microsoft 365 Copilot, a Secure Virtual Assistant for Your Computer Microsoft Introduces Researcher in Microsoft 365 Copilot, a Secure Virtual Assistant for Your Computer Cyber Security News
ClickFix Exploit Targets Windows and macOS for Malware Deployment ClickFix Exploit Targets Windows and macOS for Malware Deployment Cyber Security News
AWS Execution Roles Enable Subtle Privilege Escalation in SageMaker and EC2 AWS Execution Roles Enable Subtle Privilege Escalation in SageMaker and EC2 Cyber Security News
North Korean Phishing Campaign Exploits GitHub as C2 Tool North Korean Phishing Campaign Exploits GitHub as C2 Tool Cyber Security News
New Hpingbot Abusing Pastebin for Payload Delivery and Hping3 Tool to Launch DDoS Attacks New Hpingbot Abusing Pastebin for Payload Delivery and Hping3 Tool to Launch DDoS Attacks Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • AWS Phishing Kit Exploits MFA for Real-Time Access
  • Russia’s Use of Cellebrite to Access Activist’s iPhone
  • Microsoft Secure Boot Certificate Expiry Impacts Billions
  • Curl’s 25-Year Security Flaw Patched in Major Update
  • Popular Chrome Ad Blocker Raises Security Concerns

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • AWS Phishing Kit Exploits MFA for Real-Time Access
  • Russia’s Use of Cellebrite to Access Activist’s iPhone
  • Microsoft Secure Boot Certificate Expiry Impacts Billions
  • Curl’s 25-Year Security Flaw Patched in Major Update
  • Popular Chrome Ad Blocker Raises Security Concerns

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark