‘Uptick In Attacks’—Amazon Weaponized As Compromised Credentials Used

TL;DR AI
2 min readKey summary
Kaspersky says phishing campaigns are abusing stolen AWS IAM credentials to send bulk email through Amazon SES.
Because the messages come from trusted cloud infrastructure, they can pass standard checks like SPF, DKIM, and DMARC.
This makes the phishing emails look more legitimate and harder for filters and users to spot.
Attackers are using the setup for fraud and data theft, including invoice-themed lures.



