Behind the console: An AiTM phishing kit harvesting AWS console credentials and beyond (opens in new tab)
Datadog Security Research investigates a June 2026 adversary-in-the-middle phishing campaign that cloned the AWS console login page to harvest victim credentials and multi-factor authentication codes.
Read the original article