Malicious Google Ads being used to smuggle AWS phishing sites into search results

Share post:

A new type of phishing attack has been discovered, in which malicious Google ads are used to insert AWS phishing sites into search results. Sentiel Labs’ security researchers made the discovery.

On January 30, 2023, Sentinel Labs analysts discovered the malicious search results. When searching for “aws,” the ads came in second, just behind Amazon’s own promoted search result.

The phishing attack works by redirecting users from a legitimate-looking Google ad to a bogus Amazon Web Services login page. The spoof login page is designed to look exactly like the real AWS login page, duping users into entering their login credentials. Once the attacker has the login credentials, he or she can access the victim’s AWS account and steal sensitive data.

The malicious Google ads reroute victims to a blogger website under the attacker’s control, which is a copy of a legitimate vegan food blog at “us1-eat-a-w-s.blogspot[.]com”. After being redirected to the fake blog, the user is prompted to log in using their AWS credentials. The attackers use this information to gain access to the victim’s AWS account, from which they can steal sensitive data and engage in other malicious activities.

When the user arrives at the bogus website, they are prompted to enter their AWS credentials by selecting whether they are a root or IAM user and then entering their email address and password. This information is used by the attackers to gain access to the victim’s AWS account and steal sensitive information.

The sources for this piece include an article in BleepingComputer.

Featured Tech Jobs

SUBSCRIBE NOW

Related articles

Cyber Security Today, March 27, 2024 – A botnet exploits old routers, a new malware loader discovered, and more warnings about downloading code from...

This episode reports on a new network of 40,000 infected small and home office routers and other devices that are part of a criminal botnet

Cyber Security Today, March 25, 2024 – A suspected China threat actor going after unpatched F5 and ScreenConnet installations

This episode reports on a new campaign stealing email passwords ,the latest data breaches

A hacker’s view of the civic infrastructure: Hashtag Trending, the Weekend Edition for March 23rd, 2024

What does the civic infrastructure look like through the eyes of a hacker? The legendary general Sun Tzu in the Art of War said that in order to defeat your enemy, you must first understand your enemy. How do you do this? He said, “to know your enemy, you must become your enemy.” If we

Cyber Security Today, Week in Review for week ending Friday, March 22, 2024

This episode features discussion on lessons learned from the ransomware attack on the British Library, advice for managing expectations of IT/security teams, why firms are leaving Google Firebase unprotecte

Become a member

New, Relevant Tech Stories. Our article selection is done by industry professionals. Our writers summarize them to give you the key takeaways