PULSE NAME
IOC - Cloud Abuse at Scale TruffleNet, AWS SES, and Business Email Compromise
WHITE celestre 2025-11-04 Modified: 2025-12-04
5
IOCs
LOW VOLUME
Identity compromise remains one of the most pressing threats to cloud infrastructure today. When attackers gain access to valid credentials, they can often bypass the traditional security controls designed to protect those environments. In AWS, this type of compromise frequently manifests through abuse of the Simple Email Service (SES), one of the most common tactics observed in real-world intrusions. SES offers adversaries a convenient and scalable way to conduct illicit email operations once they’ve obtained valid AWS access keys.
Indicators of Compromise (5)
All domain
TYPEINDICATORDESCRIPTIONCREATED
domain cdnbenin.com 2025-11-04
domain cfp-impactaction.com 2025-11-04
domain majoor.co 2025-11-04
domain novainways.com 2025-11-04
domain restaurantalhes.com 2025-11-04