https://cairoict.com/trade-visitor-registration/ https://cairoict.com/trade-visitor-registration/ https://cairoict.com/trade-visitor-registration/
الإثنين, 21 سبتمبر, 2026
سياسة الخصوصية
من نجن
No Result
View All Result
  • آخر الأخبار
  • أمن إلكتروني
  • خدمات مالية
  • تقنيات ومنصات
  • ريادة أعمال
  • عالم الألعاب
  • مدن المستقبل
  • أحدث المنتجات
  • ترند
  • English
Techno fin
No Result
View All Result
  • آخر الأخبار
  • أمن إلكتروني
  • خدمات مالية
  • تقنيات ومنصات
  • ريادة أعمال
  • عالم الألعاب
  • مدن المستقبل
  • أحدث المنتجات
  • ترند
  • English

Kaspersky Warns of Amazon SES Phishing Attacks

by تكنو فن
مايو 11, 2026
Reading Time: 5 mins read
A A
Amazon

Kaspersky has uncovered a new wave of sophisticated phishing and business email compromise (BEC) attacks that exploit Amazon Simple Email Service (SES), a cloud-based email platform used for sending large volumes of transactional and marketing emails.

The cybersecurity firm warns that attackers are leveraging the trusted infrastructure of Amazon to make fraudulent emails appear legitimate and significantly harder to detect.

Exploiting Amazon SES infrastructure for cyberattacks

Amazon SES operates through highly trusted IP addresses and often includes legitimate identifiers such as “.amazonses.com,” which makes malicious emails difficult to distinguish from genuine corporate communications.

This level of trust in Amazon’s infrastructure allows cybercriminals to conduct large-scale phishing campaigns while bypassing traditional email security filters.

RelatedPosts

Money20/20 Middle East Charts Saudi Fintech Future

Cairo Design Week 2026 to Host MENA’s First Cross-Border Design Collective

NetApp Reinforces Commitment to Egypt’s Digital Future Through CONNECT Cairo 2026

Stolen AWS credentials at the core of the attacks

According to Kaspersky, the attacks rely heavily on stolen AWS Identity and Access Management (IAM) credentials, often leaked through public repositories, misconfigured cloud storage, or exposed configuration files.

Once obtained, attackers use automated tools to identify active credentials and exploit them to send large volumes of phishing emails through Amazon’s legitimate cloud infrastructure.

Advanced techniques to hide malicious activity

Cybercriminals are masking malicious links behind trusted domains such as amazonaws.com, using redirect chains and carefully crafted HTML-based email designs to make the messages appear professional and credible.

In many cases, phishing pages are hosted on trusted cloud infrastructure, further increasing their legitimacy and making detection more difficult.

Campaigns impersonating trusted services like DocuSign

Kaspersky researchers also identified phishing campaigns impersonating widely used document signing services such as DocuSign.

Victims are typically asked to review or sign documents, but are redirected to fake login pages hosted on Amazon cloud services, where their credentials are stolen.

Business Email Compromise (BEC) attacks via Amazon SES

In addition to phishing, attackers are using Amazon SES to conduct Business Email Compromise (BEC) campaigns by impersonating company employees and creating fake email threads with vendors.

These attacks often target finance departments with urgent payment requests and include PDF attachments containing banking details, avoiding suspicious links to bypass security checks.

Security experts warn of increasing sophistication

Roman Dedenok, spam analysis expert at Kaspersky, said that abusing trusted platforms like Amazon SES represents an advanced evolution in cyberattacks.

He explained that attackers are no longer just using notification systems but are directly compromising cloud credentials to control legitimate infrastructure and send highly convincing fraudulent emails.

Kaspersky recommendations to reduce risk

Kaspersky advises organizations to strengthen their cloud security posture by:

  • Minimizing AWS permissions and applying least-privilege access
  • Replacing static IAM keys with role-based authentication
  • Enabling multi-factor authentication (MFA)
  • Restricting access by IP address where possible
  • Regularly rotating and reviewing credentials
  • Avoiding trust based solely on sender name or domain
  • Verifying unexpected emails through alternative communication channels
  • Carefully inspecting links before clicking, even from trusted services

Growing threat from cloud-based phishing

These attacks highlight a broader trend of cybercriminals increasingly abusing trusted cloud infrastructures to conduct phishing campaigns.

As cloud services become more deeply integrated into business operations, security experts warn that organizations must adopt stronger identity management and monitoring systems to defend against evolving threats.

شارك هذا الموضوع

  • المشاركة على WhatsApp (فتح في نافذة جديدة) WhatsApp
  • المشاركة على Telegram (فتح في نافذة جديدة) Telegram
  • المزيد
  • تدوينة
  • Tweet

مرتبط

Tags: Amazon SESAWS securityBEC attackscybersecurityemail fraudKasperskyphishing attacks

Related Posts

Money20/20 Middle East Charts Saudi Fintech Future
English

Money20/20 Middle East Charts Saudi Fintech Future

سبتمبر 17, 2026
Cairo Design Week
English

Cairo Design Week 2026 to Host MENA’s First Cross-Border Design Collective

يونيو 22, 2026
NetApp
English

NetApp Reinforces Commitment to Egypt’s Digital Future Through CONNECT Cairo 2026

يونيو 21, 2026
English

POPCORN Launches AI Platform for Arabic Video Ad Production

يونيو 11, 2026
Load More

آخر الأخبار

الذهب

الذهب يصعد 110 جنيهات في أسبوع

سبتمبر 20, 2026
سعر الفضة

الفضة تصعد 3.94% في أسبوع

سبتمبر 20, 2026
اتش سي تتوقع رفع الفائدة 100 نقطة أساس

اتش سي تتوقع رفع الفائدة 100 نقطة أساس

سبتمبر 20, 2026
أڤيڤا تدعم التحول الرقمي لقطاع التعدين المصري

أڤيڤا تدعم التحول الرقمي لقطاع التعدين المصري

سبتمبر 20, 2026
«باور وادي» تطلق حلول «وادي» للطاقة

«باور وادي» تطلق حلول «وادي» للطاقة

سبتمبر 20, 2026
No Result
View All Result
contact us: info@techno-fin.com Dubai:0553028804 Cairo:01150009990

Follow Us

All rights reserved to www.techno-fin.com, UAE, Sheikh Zayed Road, City Tower 2, 18th floor, office 1801
No Result
View All Result
  • آخر الأخبار
  • أمن إلكتروني
  • خدمات مالية
  • تقنيات ومنصات
  • ريادة أعمال
  • عالم الألعاب
  • مدن المستقبل
  • أحدث المنتجات
  • ترند
  • English