Suspicious AWS AiTM Phishing Kit Endpoint Access via Proxy

PremiumReviewedSigma · Medium · v1
Category
proxy
Author
HuntRule
Published
2026-09-15
Updated
2026-09-15

ATT&CK techniques

Initial Access → Collection
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Discovery

  9. Lateral Movement

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule detects web requests carrying the input_24 parameter to the /api endpoints used by the AWS adversary-in-the-middle phishing kit, which relays victim credentials and MFA responses to the legitimate AWS console. The kit exposes paths such as /api/check, /api/login and /api/auth alongside MFA relay branches for email, sms and gauth. Detecting these accesses is important because they indicate users interacting with a live credential-and-session-stealing phishing site.

Related detections9 linkedT1557 — drag to rearrange
Suspicious AiTM Phishing Kit Session Validation Endpoint via Proxy
Suspicious AWS Console AiTM Phishing Kit API Endpoints
Suspicious AWS Console Phishing MFA Relay Endpoints
Possible AiTM Phishing Sign-On Evaluation Denied by Okta FastPass
Suspicious Azure AD MFA Fatigue Repeated Push Denials
Malicious Evilginx AiTM Phishing Proxy Default TLS Certificate
Malicious Office 365 Email Rule Breach - On Behalf (via office365)
Suspicious Sneaky 2FA Phishing Kit License Check via API Key Endpoint (via proxy)
Malicious TCP Session Hijacking via rshijack
Suspicious AWS AiTM Phishing Kit Endpoint Access via Proxy
Pivot detection · T1557 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.