Datadog Security Labs reported a targeted adversary-in-the-middle phishing campaign that impersonated the AWS sign-in experience to steal console credentials and capture MFA codes in real time, enabling attackers to hijack active sessions. The operation used at least three AWS-themed domains registered through NICENIC INTERNATIONAL GROUP CO., LIMITED and hosted behind Cloudflare, with cloned login pages and server-side logic that handled email, SMS, and authenticator-app MFA prompts. Phishing emails posing as AWS Support were sent through legitimate delivery services including SendGrid and Nimbu to improve deliverability and credibility.
Researchers said the kit rendered pages only for pre-validated targets using an encrypted URL parameter, input_24, a gating method that likely tied each link to a specific victim and reduced exposure to sandboxes and scanners. Fewer than 50 target addresses were recovered, most tied to US-based software engineers and engineering leaders, and investigators also found a likely attacker validation batch file on VirusTotal. Datadog linked the infrastructure and tradecraft to a broader phishing-kit family previously used in campaigns impersonating SendGrid, Salesforce, and cryptocurrency wallet brands, indicating a reused and increasingly refined framework that defenders should track through suspicious DNS activity and anomalous AWS CloudTrail ConsoleLogin events.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
Datadog disclosed that the phishing kit used cloned AWS sign-in pages, relayed victim logins to the legitimate AWS flow, and gated page rendering with an encrypted URL parameter to restrict access to pre-validated targets. The report also noted phishing delivery through legitimate services such as SendGrid and Nimbu and identified fewer than 50 recovered target addresses.
Researchers identified at least three AWS-themed phishing domains registered within a 48-hour window through NICENIC INTERNATIONAL GROUP CO., LIMITED and hosted on Cloudflare as part of the campaign infrastructure.
Datadog Security Research observed a targeted adversary-in-the-middle phishing campaign against AWS users that harvested console credentials and captured MFA codes in real time. The activity was observed between June 16 and 19, 2026, and targeted primarily US-based engineering personnel.
Datadog linked the AWS-themed infrastructure and tradecraft to a broader phishing kit family that had previously impersonated brands such as SendGrid, Salesforce, and cryptocurrency wallets since at least July 2025.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
6 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcecybersecuritynews.com
Open sourcesecuritylabs.datadoghq.com
Open sourcedocs.datadoghq.com
Open sourcedocs.datadoghq.com
Open sourceblog.nviso.eu
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.