
Researchers from Datadog Security Labs have warned of an active phishing campaign targeting AWS account holders. This campaign uses Adversary-in-the-Middle (AiTM) techniques and typosquatted domains to bypass multi-factor authentication (MFA) and hijack administrative access.
Campaign Details
The attack has been active since late February 2026 and targets cloud administrators, DevOps engineers, and security teams.
noreply@security[.]aws, warning of a security alert.aws-security-portal[.]com instead of the official console).How the AiTM Hijack Works
The campaign leverages sophisticated AiTM phishing kits (such as Tycoon2FA) that function as a reverse proxy.
Speed of Attack
Researchers observed that once credentials were submitted, attackers authenticated to the compromised AWS account in as little as 20 minutes. Once inside, these accounts are often used for unauthorized resource provisioning, data exfiltration, or crypto-mining operations.
Mitigation Strategies
#accounts #aitm #and #aws #domains #hijacked #news #phishing #typosquatted #via — News
© Bulletproof Servers. All rights reserved.