Back to Intel

Intel Node

“Legitimate” phishing: how attackers weaponize Amazon SES to bypass email security

lowadvisory2026-05-04T10:00:23+00:00source excerpt
tradecraftcloudidentityemail

Source excerpt · The upstream feed supplied only part of this article.Read the original source →

Kaspersky expert breaks down a new phishing scheme that uses the Amazon SES cloud email service. Let's look at some examples to see how you can tell a phishing email from a real one.

Introduction The primary goal for attackers in a phishing campaign is to bypass email security and trick the potential victim into revealing their data. To achieve this, scammers employ a wide range of tactics, from redirect links to QR codes. Additionally, they heavily rely on legitimate sources for malicious email campaigns. Specifically, we’ve recently observed an uptick in phishing attacks leveraging Amazon SES. The dangers of Amazon SES abuse Amazon Simple Email Service (Amazon SES) is a cloud-based email platform designed for highly reliable transactional and marketing message delivery.

It integrates seamlessly with other products in Amazon’s cloud ecosystem, AWS. At first glance, it might seem like just another delivery channel for email phishing, but that isn’t the case.

Read Original Source