Tag: AWS Misconfigurations

Hackers Exploit AWS Misconfigurations to Launch Phishing Attacks via SES and WorkMail
News

Hackers Exploit AWS Misconfigurations to Launch Phishing Attacks via SES and WorkMail

According to research from Palo Alto Networks Unit 42, threat actors are focusing on Amazon Web Services (AWS) settings in order to distribute phishing attempts to unwary targets. The activity cluster is being monitored by the cybersecurity firm under the moniker TGR-UNK-0011, which stands for a threat group with unclear motive. The company claims that this group overlaps with JavaGhost. Since 2019, TGR-UNK-0011 has been known to be operational. Historically, the organization concentrated on vandalizing websites, according to security expert Margaret Kelley. They switched to sending phishing emails in 2022 in order to make money. It is important to note that these attacks do not take use of any AWS vulnerabilities. Instead, the threat actors use environmental misconfigurations th...