Misconfigured AWS Accounts Are Fueling Phishing Campaigns
eSecurity Planet
MARCH 4, 2025
The attackers, identified as TGR-UNK-0011, or JavaGhost, leverage exposed AWS credentials to gain access to cloud accounts and use legitimate services like Amazon Simple Email Service (SES) and WorkMail to distribute phishing messages. Setting up SES and WorkMail accounts to send phishing emails that appear legitimate.
Let's personalize your content