Targeted AWS Phishing Campaign Captures Credentials and MFA Codes

Targeted AWS Phishing Campaign Captures Credentials and MFA Codes

First seen 26 Jun 2026, 04:08 UTC GbhackersCybersecuritynewsEscudodigital 80% similarity 71.0
Share:

Article Content

Browse articles
ThreatCluster

A sophisticated phishing campaign targeting Amazon Web Services (AWS) users has emerged, utilizing cloned login pages to capture credentials and multifactor authentication (MFA) codes in real-time. The attackers have focused on nearly fifty specific targets, primarily software engineers in the U.S., and have been active since mid-2025. The phishing emails impersonate AWS technical support, prompting users to click on malicious links that lead to fake login pages. Once victims enter their credentials, the attackers intercept MFA codes, allowing them to hijack active sessions. The phishing infrastructure leverages legitimate email services and Cloudflare to evade detection. Researchers have identified several domains used in this campaign that mimic official AWS services, marking them as indicators of compromise. This targeted approach indicates a highly selective operation rather than a broad attack. The campaign's sophistication raises significant concerns for AWS users and organizations relying on cloud services.

Key Points: • Phishing campaign targets AWS users, capturing credentials and MFA codes in real-time. • Attackers impersonate AWS support in emails, leading victims to cloned login pages. • Infrastructure utilizes legitimate services like Cloudflare to bypass detection.

ThreatCluster AI

Timeline

2025-01-01
Phishing infrastructure established
Attackers began using cloned AWS login pages to capture user credentials and MFA codes.
Escudodigital
2025-06-01
Target list compiled
Nearly fifty specific targets, mainly U.S. software engineers, were identified for the phishing campaign.
Escudodigital
2026-06-25
Campaign reported
Multiple cybersecurity outlets reported on the sophisticated phishing campaign targeting AWS users.
Gbhackers
2026-06-25
Phishing kit details revealed
A newly discovered phishing kit was reported to be actively stealing AWS console credentials in real-time.
Cybersecuritynews

Community

Browse all →