Attackers orchestrated a large-scale campaign leveraging stolen credentials to compromise Amazon Web Services (AWS) Simple Email Service (SES) accounts and Portainer instances, enabling the control of over 800 malicious hosts. The campaign, dubbed TruffleNet, utilized the open source TruffleHog tool to systematically test compromised credentials and perform reconnaissance across AWS environments, facilitating business email compromise (BEC) and other malicious activities.
Threat actors exploited Portainer, a legitimate container management tool, as a lightweight control panel to coordinate their infrastructure, making it easier to manage and deploy malicious operations at scale. The campaign highlights the risks associated with exposed cloud management interfaces and the abuse of legitimate DevOps tools for orchestrating attacks, underscoring the need for organizations to secure cloud credentials and restrict access to management dashboards like Portainer.

Get the infrastructure and lures behind it.
1 event from the most recent confirmed update back to the earliest known activity.
On November 3, 2025, reporting described the TruffleNet campaign as using stolen credentials to abuse AWS services, including SES, and Portainer-managed infrastructure. The campaign was said to orchestrate more than 800 malicious hosts in support of business email compromise and related malicious activity.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.