Tag: Amazon SES

Amazon SES increasingly abused in phishing to evade detection
News

Amazon SES increasingly abused in phishing to evade detection

A growing number of phishing emails are being sent via the Amazon Simple Email Service (SES), which can evade common security filters and make reputation-based blocking useless. The recent rise may be caused by a significant number of AWS Identity and Access Management access keys exposed in public assets, even when the resource has previously been used for nefarious activities. Phishing operations can utilize Amazon SES to deliver malicious emails that evade authentication checks because it is a reliable and authentic resource. In a paper released today, Kaspersky researchers warn that they have "observed an uptick in phishing attacks leveraging Amazon SES" to deliver links that lead to malicious websites. The growing exposure of AWS credentials in GitHub repositories,.ENV fi...