A sophisticated malicious campaign has emerged, exploiting Amazon SES (Simple Email Service) to orchestrate widespread phishing attacks, capable of delivering over 50,000 malicious emails daily.

This attack represents a significant development in the abuse of cloud services, turning AWS's legitimate bulk email platform into a weapon for credential theft and financial fraud.
The campaign begins with the acquisition of compromised AWS access keys, which are obtained through common attack paths, such as public exposure of code repositories, misconfigured cloud assets, or theft from developer workstations.
Once adversaries have obtained these credentials, they immediately proceed to scan the environment using GetCallerIdentity requests to assess available permissions, specifically targeting accounts with SES-related names (which indicate access to the email service).
See also: GhostAction campaign steals 3325 secrets in GitHub attack
Wiz.io researchers discovered this campaign in May 2025 after detecting unusual patterns in AWS API activity across multiple regions.
The attackers implemented a multi-regional approach, simultaneously issuing PutAccountDetails requests to all AWS regions within seconds (to escape SES “sandbox” restrictions).
This technique, which has not been previously documented, allows malicious users to bypass the typical 200 email per day limit and unlock production mode capabilities.
The phishing infrastructure targets victims with persuasive tax-related content, using subject lines such as “Your 2024 Tax Form(s) Are Now Ready to View and Print.”.

These messages redirect users to websites credential harvesting hosted on domains such as irss.securesusa.com, using commercial traffic analysis services to hide the malicious infrastructure and evade traditional security scanners.
Amazon SES Abuse: Technical Infrastructure and Avoidance Mechanisms
Attackers create their email infrastructure through systematic domain verification using the CreateEmailIdentity API.
They register both domains controlled by the attackers, such as managed7.com, street7news.org, and docfilessa.com, as well as legitimate domains with weak DMARC configurations that facilitate email spoofing.
See also: Salesloft Drift attack linked to GitHub breach
Each verified domain supports multiple email addresses using standard prefixes like admin@, billing@, and noreply@ to look legitimate in recipients' inboxes.
🔑 Secure your passwords with Proton Pass
Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.
- ✔ Encrypted storage of passwords & passkeys
- ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
- ✔ Free version — on all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
The technical complexity of the campaign extends to automated privilege escalation efforts.
When standard production limits proved insufficient, the attackers created support tickets via the CreateCase API and attempted to create IAM policies named “ses-support-policy” to gain elevated privileges.
Although these scaling attempts failed due to insufficient privileges, the daily limit of 50,000 emails was sufficient for their operational requirements.
This Amazon SES abuse demonstrates how cloud services designed for legitimate business purposes can be weaponized on a large scale, highlighting the critical need for enhanced monitoring of inactive access keys and unusual API activity patterns across multiple regions in cloud environments.
See also: Over 6,700 private repositories exposed in Nx attack

This particular malicious campaign clearly demonstrates how the concept of “security through trust” breaks down when cloud services are weaponized in the hands of attackers. The most concerning aspect is not just the volume of emails that can be sent, but the fact that the attackers are so effective at manipulating AWS’s own mechanisms, mimicking normal API usage. This makes it extremely difficult for traditional detection mechanisms to distinguish legitimate from malicious activity.
At the same time, the use of tax issues as bait highlights the strategic choice of hackers to exploit users’ anxiety and obligations. When an email appears to come from a service like Amazon, and even with a domain that passes basic authentication checks, the likelihood of deception is much higher. The problem is not limited to individual users; it concerns entire business ecosystems that rely on the integrity of the cloud.
Ultimately, the Amazon SES abuse shows that attackers don’t need to build their own infrastructure; they just need to cleverly direct the tools of the cloud itself against us. The question remains whether service providers can prevent the next level of abuse before trust in the cloud is irreparably damaged.
