As cited
Copy frozen at (site build).
threat intel
Behind the console: An AiTM phishing kit harvesting AWS console credentials and beyond
Datadog Security Research identified a phishing campaign in June 2026 that cloned the AWS console login page to intercept user credentials and multifactor authentication (MFA) codes via adversary-in-the-middle (AiTM) techniques. The attackers captured both authentication factors to gain unauthorized access to AWS environments.
Why it matters: AWS users and administrators are targeted by this active phishing campaign; practitioners should implement conditional access policies, enforce hardware security keys, and monitor for suspicious login activity to AWS console access.
- Source published
- First seen by Cybersecurity Tracker