Amazon SES Weaponized for Phishing & BEC via Leaked AWS IAM Access Keys (Securelist, May 2026)
Amazon SES Weaponized for Phishing & BEC via Leaked AWS IAM (TL-2026-0451), also tracked as Amazon SES Phishing Wave 2026, is a high-severity phishing campaign, first published 2026-05-04. It has no confirmed attribution, affects Amazon Web Services Amazon Simple Email Service (SES), maps to 25 MITRE ATT&CK techniques (T1036, T1078.004, T1098.001), and is covered by 9 detection rules and 22 indicators of compromise.
Key facts for TL-2026-0451
- Threat ID
- TL-2026-0451
- Also known as
- Amazon SES Phishing Wave 2026, SES IAM Key Abuse, AWS SES BEC Campaign
- Severity
- HIGH
- Status
- ACTIVE
- Category
- PHISHING
- First published
- 2026-05-04
- Last reviewed
- 2026-05-04
- Attribution confidence
- NONE
- Motivation
- FINANCIAL
- Target sectors
- financial services, professional services, technology, manufacturing, healthcare, legal, real estate, education, retail, government
- Target regions
- Global, North America, Europe, Asia-Pacific, Latin America, Middle East
- Detection rules
- 9
- Indicators of compromise
- 22
Malware and tooling in Amazon SES Weaponized for Phishing & BEC via Leaked AWS IAM
Malware and tooling: AWS CLI / AWS SDK (boto3, aws-sdk-js, aws-sdk-go), Compromised Amazon SES tenant, TruffleHog - S9009
Kaspersky/Securelist documents a 2026 trend in which threat actors harvest leaked AWS IAM access keys from public GitHub repos, ENV files, Docker images, configuration backups, and open S3 buckets — primarily via TruffleHog-based bots — and then weaponize compromised Amazon SES tenants. The hijacked SES tenants emit fully SPF/DKIM/DMARC-authenticated phishing and BEC emails carrying .amazonses.com Message-ID headers and amazonaws.com-hosted phishing landing pages, defeating reputation-based controls and AP/finance review. Observed lures include fake DocuSign signature requests and fabricated employee-vendor invoice threads driving urgent wire transfers.
How Amazon SES Weaponized for Phishing & BEC via Leaked AWS IAM works
OVERVIEW In early 2026, Kaspersky's Roman Dedenok (Securelist, 2026-05-04) reported a sustained uptick in phishing and Business Email Compromise (BEC) campaigns abusing Amazon Simple Email Service (Amazon SES). Unlike commodity phishing that depends on freshly registered look-alike domains and quickly blocklisted infrastructure, this trend hinges on hijacking legitimate AWS tenants. The attacker piggybacks on Amazon's reputation, authentication footprint, and IP space. Because emission occurs from real AWS-owned IPs, with valid SPF/DKIM signatures and aligned DMARC, the messages bypass reputation, header-based, and protocol-level email defenses that secure operations centers traditionally rely upon.
INITIAL ACCESS — IAM ACCESS KEY HARVESTING The campaign begins with credential acquisition rather than exploitation. Phisher infrastructure runs automated scrapers built around the open-source secret-detection utility TruffleHog and similar tools, continuously enumerating public GitHub repositories, mirror sites (e.g., GitHub commit history, gist.github.com), public S3 buckets, leaked Docker image layers (via Docker Hub and self-hosted registries), and exposed environment files (.env, config.yml, docker-compose.yml). Long-lived AWS IAM access keys, especially with patterns matching `AKIA[0-9A-Z]{16}`, are tested against AWS APIs to determine permission scope and SES sending limits (`GetSendQuota`, `ListIdentities`, `GetAccount`). Keys with attached `AmazonSESFullAccess`, `ses:SendEmail`, or overly permissive admin policies are retained for weaponization.
WEAPONIZATION — SES TENANT ABUSE Once a valid key is identified, attackers use the AWS SDK or smtp credentials derived from the IAM key (Amazon SES SMTP credentials are deterministically derived from the IAM secret access key) to issue `SendEmail`, `SendBulkTemplatedEmail`, and `SendRawEmail` API calls. Custom HTML templates supplied via SES enable convincing brand impersonation. Because the legitimate tenant is already verified for one or more sender domains and has DKIM signing keys provisioned in Route53 (or equivalent DNS), every outbound message carries valid DKIM-Signature, an `X-SES-Outgoing` header, and a Message-ID of the form `<UUID@email.amazonses.com>` or `<UUID@*.amazonses.com>`. SPF passes via Amazon's published `_spf.amazonses.com` include directives. Provided the tenant's DMARC record is `p=none`/`p=quarantine`, the abusing email aligns and passes DMARC.
LURE CATALOG — DOCUSIGN AND BEC In observed campaigns, two lure categories dominate: (1) Fake DocuSign / electronic-signature notifications inviting the victim to review and sign a document. The link in the email is masked as an `amazonaws.com` URL — typically a public S3 bucket or an `*.s3.amazonaws.com` static site hosting the phishing form — which redirects to or directly serves a credential-harvesting page styled after Microsoft 365, Google Workspace, or DocuSign sign-in. (2) BEC variants in which the attacker fabricates an entire reply chain between an internal employee and an external service provider regarding an outstanding invoice. The body contains the forwarded thread; PDF attachments include payment details and forged supporting documentation. Crucially, the PDFs in observed BEC samples carry no malicious URLs or QR codes — they are passive financial fraud documents intended to anchor the social-engineering ask. The email is addressed to finance / accounts payable, requesting urgent wire transfer to an attacker-controlled bank account.
WHY EMAIL CONTROLS FAIL Standard defensive layers — sender reputation, IP blocklists, SPF/DKIM/DMARC enforcement, and even some BEC-tuned ML detectors that flag domain-anomaly senders — under-detect this campaign because: (a) the sending IP belongs to AWS (e.g., 23.249.208.0/20, 67.231.144.0/20, 199.122.120.0/22 SES ranges) and cannot safely be blocklisted; (b) authentication results report `dkim=pass header.d=<victim-tenant-domain>` and `spf=pass`; (c) Message-ID `.amazonses.com` is widely associated with legitimate transactional mail, so its presence is a positive trust signal in many SOC playbooks; (d) outbound link clicks resolve to `amazonaws.com` which most secure web gateways categorize as `cloud-services` or `business-and-economy`. The attacker is, in effect, borrowing the victim tenant's earned reputation.
DEFENDER LEVERAGE POINTS The defensive opportunity sits at four control planes: AWS-side (IAM hygiene, key rotation, MFA, IP-restricted policies, CloudTrail SES anomaly detection, GuardDuty `Recon:IAMUser/MaliciousIPCaller` and `Stealth:IAMUser` findings); developer pipeline (pre-commit secret scanners, GitHub push-protection, Docker image scanning); inbound email (header-level inspection of `X-SES-Outgoing`, sudden tenant-domain change in `dkim=pass header.d`, link-rewriting/sandboxing of amazonaws.com links, attachment defanging); and finance process (out-of-band verification for any wire-transfer change, especially when the request originates from an internal employee impersonation). For sending tenants, Amazon's `ListIdentities`, `GetSendStatistics`, `GetSendQuota`, and SES Event Publishing (CloudWatch / SNS bounces, complaints, deliveries) provide ground truth on whether their tenant is being abused.
ATTRIBUTION Kaspersky/Securelist did not attribute the activity to a named actor. The tradecraft (mass IAM key harvesting + SES abuse + Docusign-themed lures + BEC) overlaps with multiple financially motivated clusters historically tracked under labels such as TA4903, TA4557, and various BEC actors. Attribution is therefore listed as Unknown with LOW confidence pending hash, infrastructure, or actor-overlap evidence.
MITRE ATT&CK techniques used in TL-2026-0451
Defense Evasion
T1036 Masquerading; T1684.001 Impersonation
Initial Access
T1078.004 Valid Accounts: Cloud Accounts; T1566 Phishing; T1566.001 Phishing: Spearphishing Attachment; T1566.002 Phishing: Spearphishing Link
Persistence
T1098.001 Account Manipulation: Additional Cloud Credentials
Command and Control
Collection
T1213.003 Data from Information Repositories: Code Repositories
Impact
T1496 Resource Hijacking; T1657 Financial Theft
Discovery
T1526 Cloud Service Discovery; T1580 Cloud Infrastructure Discovery
Lateral Movement
Credential Access
T1552.001 Unsecured Credentials: Credentials In Files; T1552.004 Unsecured Credentials: Private Keys; T1552.005 Unsecured Credentials: Cloud Instance Metadata API
Resource Development
T1583.006 Acquire Infrastructure: Web Services; T1585.002 Establish Accounts: Email Accounts; T1586 Compromise Accounts; T1586.003 Compromise Accounts: Cloud Accounts; T1608.002 Stage Capabilities: Upload Tool
Reconnaissance
T1593 Search Open Websites/Domains; T1593.003 Search Open Websites/Domains: Code Repositories; T1596 Search Open Technical Databases
Affected products and versions in Amazon SES Weaponized for Phishing & BEC via Leaked AWS IAM
- Amazon Web Services — Amazon Simple Email Service (SES)
Vulnerable versions: all regions, any tenant with leaked or weakly scoped IAM access key
Fixed in: N/A — service is not flawed; abuse hinges on customer credential hygiene - Amazon Web Services — AWS Identity and Access Management (IAM)
Vulnerable versions: any account with long-lived IAM access keys, no MFA, and overly permissive ses:* policies
Fixed in: N/A — control is on the customer side - Amazon Web Services — Amazon S3
Vulnerable versions: public buckets used for static phishing pages or credential leak storage
Fixed in: block public access settings; bucket policies enforcing private ACLs - DocuSign — DocuSign brand (impersonated)
Vulnerable versions: DocuSign brand abused in lure templates, no product flaw
Fixed in: N/A
Remediation for Amazon SES Weaponized for Phishing & BEC via Leaked AWS IAM
Patches
- No software patch applies — this is an abuse-of-legitimate-service trend, not a vulnerability. Mitigation is configuration, hygiene, and detection.
Immediate actions
- Rotate all AWS IAM access keys older than 90 days; immediately revoke any IAM access key found in source repositories, build artifacts, container images, or backups
- Enable AWS GuardDuty in every account and ensure findings include 'CredentialAccess', 'Recon:IAMUser/MaliciousIPCaller', 'UnauthorizedAccess:IAMUser/MaliciousIPCaller' and 'Stealth:IAMUser/CloudTrailLoggingDisabled'
- Audit Amazon SES sending identities via 'aws ses list-identities', 'aws ses get-send-quota', 'aws ses get-send-statistics' across all regions; investigate any tenant whose 24-hour sent-email volume deviates >2σ from baseline
- Block or rewrite click-time amazonaws.com and *.s3.amazonaws.com links at the secure email gateway / SWG so that they undergo URL detonation rather than implicit allow
- Implement AP / finance out-of-band verification policy for any wire-transfer payment change request received via email, even when SPF/DKIM/DMARC pass
- Add inbound mail rule to flag (not block) external email containing both 'X-SES-Outgoing' header and a body link to amazonaws.com / s3.amazonaws.com for SOC review
Workarounds
- Restrict SES sending to specific source IP CIDRs using the 'aws:SourceIp' IAM policy condition where business viability allows
- Enable AWS SES sandbox mode in non-production accounts to cap blast radius if a key leaks
- Add a permissive but logged DMARC reporting endpoint (rua=mailto:dmarc-reports@) on every tenant domain so that abnormal volume triggers alerts
Longer-term hardening
- Eliminate long-lived IAM access keys: enforce IAM Identity Center (formerly AWS SSO) federation, EC2 instance roles, EKS IRSA, and Lambda execution roles for all programmatic access
- Apply principle of least privilege to all SES access — replace 'AmazonSESFullAccess' with scoped policies that restrict 'ses:SendEmail' and 'ses:SendRawEmail' to specific FromAddress conditions
- Require MFA on the AWS root account and all IAM users; use 'aws:MultiFactorAuthPresent' condition keys on sensitive policies
- Configure AWS Config managed rule 'iam-user-unused-credentials-check' (max 90 days) and 'access-keys-rotated' (max 90 days)
- Deploy CloudTrail organization trails with S3 + KMS + CloudWatch log delivery; set Athena queries for SES API calls from new IPs/UA
- Mandate GitHub push-protection, GitHub secret scanning with custom patterns, and pre-commit hooks (gitleaks, trufflehog, detect-secrets) in CI/CD
- Scan Docker images and registries continuously (Trivy, Grype, Docker Scout) for secrets in layers and ENV directives
- Adopt AWS Key Management Service (KMS) and AWS Secrets Manager / Parameter Store for any developer-held credential
- Train AP/finance and front-line employees on BEC patterns where sender authentication passes but the request itself is anomalous
Weaknesses (CWE) in Amazon SES Weaponized for Phishing & BEC via Leaked AWS IAM
CWE-798, CWE-522, CWE-200, CWE-540, CWE-256, CWE-538
Timeline of Amazon SES Weaponized for Phishing & BEC via Leaked AWS IAM
- Amazon Web Services launches Amazon Simple Email Service (SES), positioning it as a high-deliverability transactional and marketing mail platform integrated with the AWS ecosystem.
- TruffleHog is publicly released as an open-source secret-scanning utility, enabling automated discovery of API keys and credentials in Git history. It later becomes a workhorse for both defenders and credential-harvesting bots.
- Capital One breach (CVE-2019-XXXXX equivalent — SSRF on misconfigured WAF) demonstrates the operational impact of leaked or accessible AWS credentials and seeds public awareness of cloud key abuse risk.
- Public reports (e.g., Permiso, Wiz, Datadog) document a wave of AWS IAM key harvesting and SES tenant abuse for outbound spam, predating the more sophisticated phishing/BEC tradecraft observed in 2026.
- Kaspersky observes growing volume of phishing emails sent via Amazon SES that pass SPF/DKIM/DMARC and carry .amazonses.com Message-ID headers, signaling a shift from isolated incidents toward a steady trend.
- Kaspersky/Securelist analysts observe DocuSign-themed phishing lures sent via Amazon SES delivering credential-harvesting forms hosted on amazonaws.com static infrastructure.
- Kaspersky investigates a BEC case where the attacker, via a hijacked SES tenant, sent a fabricated employee-vendor invoice thread with PDF attachments to the target organization's finance team requesting urgent wire transfer.
- Roman Dedenok publishes Kaspersky/Securelist write-up 'Legitimate phishing: how attackers weaponize Amazon SES to bypass email security' formalizing the trend, documenting tradecraft, and recommending mitigations.
- As of 2026-05-29, this is a live, escalating trend: multiple sources (Securelist 2026-05-04, BleepingComputer, TechRadar, ThaiCERT) confirm SES-abuse phishing/BEC via leaked AWS IAM keys rose in Q1 and spiked in May 2026. No patch is possible (legitimate-service abuse); AWS only acts on reports, and leaked keys remain widespread, so it stays active.
Sources cited for Amazon SES Weaponized for Phishing & BEC via Leaked AWS IAM
- "Legitimate" phishing: how attackers weaponize Amazon SES to bypass email security
- Amazon SES Developer Guide — Authentication and Identity Management
- Identity-based policies for Amazon SES (least-privilege examples)
- AWS Security Best Practices — IAM Access Keys
- GuardDuty finding types — IAM and credential-access related
- TruffleHog — Find leaked credentials
- MITRE ATT&CK — T1078.004 Valid Accounts: Cloud Accounts
- MITRE ATT&CK — T1552.001 Unsecured Credentials: Credentials In Files
- MITRE ATT&CK — T1566 Phishing
- MITRE ATT&CK — T1657 Financial Theft
- FBI IC3 — Business Email Compromise (BEC) Public Service Announcement
- CISA — Identifying and Mitigating Living-Off-the-Cloud Tradecraft
- Amazon SES SMTP credential derivation from IAM secret access key
More in phishing
- ScreenConnect Client Abused by Attackers via Mejuri-Themed Payment Receipt Phishing
- CSuite Phishing Operation Steals Microsoft 365 Sessions via Device-Code Phishing and Deploys ScreenConnect/Action1 RMM Tools Against US and EU Organizations
- Former US Air Force Members Odimegwu and Mogaji Sentenced Over Phishing-Driven BEC Fraud Ring Targeting 15+ Organizations
- Phishing Campaigns Abuse RMM Tools (MSP360, ScreenConnect) for Persistent Access
- AI-Enabled Social Engineering and Synthetic Media (Deepfakes) Undermining Identity Verification
Detection coverage for TL-2026-0451
As of 2026-05-04, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0451 across Splunk SPL, Microsoft KQL and Sigma, covering 22 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.