AWS Accounts Hijacked via AiTM Phishing and Typosquatted Domains
Mar 10, 2026 // 17:10 - Norina Velotta


Researchers from Datadog Security Labs have warned of an active phishing campaign targeting AWS account holders. This campaign uses Adversary-in-the-Middle (AiTM) techniques and typosquatted domains to bypass multi-factor authentication (MFA) and hijack administrative access.

Campaign Details

The attack has been active since late February 2026 and targets cloud administrators, DevOps engineers, and security teams.

  • The Lure: Victims receive a spoofed “AWS Organization Security Email,” ostensibly from noreply@security[.]aws, warning of a security alert.
  • Typosquatting: The emails contain links to typosquatted domains that closely mimic legitimate AWS URLs (e.g., using aws-security-portal[.]com instead of the official console).
  • High-Fidelity Clones: These links redirect users to a high-fidelity clone of the AWS Management Console sign-in page.

How the AiTM Hijack Works

The campaign leverages sophisticated AiTM phishing kits (such as Tycoon2FA) that function as a reverse proxy.

  • Real-time Interception: As the victim enters their credentials and MFA code on the fake page, the kit relays them to the legitimate AWS sign-in service in real time.
  • Session Theft: Once authentication is successful, the attacker captures the session cookie.
  • MFA Bypass: Armed with this cookie, the attacker can hijack the session and access the AWS account without needing the victim’s password or a second MFA prompt.

Speed of Attack

Researchers observed that once credentials were submitted, attackers authenticated to the compromised AWS account in as little as 20 minutes. Once inside, these accounts are often used for unauthorized resource provisioning, data exfiltration, or crypto-mining operations.

Mitigation Strategies

  • Hardware Security Keys: Use FIDO2-compliant hardware keys (like Yubikeys) for MFA, as they are generally resistant to AiTM attacks.
  • Domain Monitoring: Implement Digital Risk Protection to monitor and flag lookalike or typosquatted domains targeting your organization.
  • Conditional Access: Enforce policies that only allow logins from managed devices or specific geographic locations.

#accounts  #aitm  #and  #aws  #domains  #hijacked  #news  #phishing  #typosquatted  #via   —   News