216.73.216.6

From Compromised Keys to Phishing Campaigns: Inside a Cloud Email Service Takeover

· Published 04/09/2025 23:40 · Modified 05/09/2025 08:47

Export JSON

Essential information

Published
04/09/2025 23:40
Modified
05/09/2025 08:47
Tags
2025-09-04 aws cloud security email service phishing sandbox escape
Related entities
4 observables, 2 techniques (mitre)

Description

An access key compromise led to a sophisticated SES abuse campaign in May 2025. The attacker exploited the stolen key to bypass SES restrictions, verify new sender identities, and conduct a large-scale operation. They used multi-regional PutAccountDetails requests to escape the SES sandbox, a novel technique in SES abuse. The campaign involved creating multiple email identities using attacker-owned and legitimate domains with weak DMARC protections. The subsequent campaign targeted various organizations, using tax-related lures to steal credentials. This incident highlights the importance of monitoring cloud service usage, especially for services like SES that can be exploited for monetization.

External references