TruffleNet is a business email compromise and phishing operation identified for abusing Amazon Web Services Simple Email Service as a delivery platform for fraudulent email. The activity relies on stolen credentials to access cloud email-sending accounts, create new sending identities, and transmit spoofed messages that appear legitimate. Reported tradecraft also includes theft and misuse of DKIM material from compromised WordPress sites to improve email authenticity and deliverability. The operation is associated with cloud-service abuse, spoofing, credential theft, and initial access techniques in support of financially motivated fraud. No high-confidence attribution to a specific country, state sponsor, or formally tracked intrusion set is currently available.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
TruffleNet is a large-scale BEC scam operation that abuses AWS infrastructure to send phishing emails and conduct fraud, including theft of DKIM keys and use of typosquatted domains.
TruffleNet is a large-scale BEC scam operation that abuses AWS infrastructure to send phishing emails and conduct fraud, including theft of DKIM keys and use of typosquatted domains.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.