Suspicious AWS Console AiTM Phishing Kit API Endpoints

PremiumReviewedSigma · High · v1
Category
proxy
Author
HuntRule
Published
2026-05-21
Updated
2026-08-28

ATT&CK techniques

Initial Access → Collection
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Discovery

  9. Lateral Movement

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule detects requests to the AWS console phishing kit API endpoints that relay login attempts using its distinctive input_24 parameter. The adversary-in-the-middle kit proxies AWS console authentication through check, login, and auth routes to capture credentials in real time. Traffic to these kit endpoints carrying the input_24 field indicates victims interacting with the AWS console phishing infrastructure.

Related detections9 linkedT1557 — drag to rearrange
Malicious Office 365 Email Rule Breach - On Behalf (via office365)
Suspicious Sneaky 2FA Phishing Kit License Check via API Key Endpoint (via proxy)
Malicious TCP Session Hijacking via rshijack
Suspicious Entra ID Auth Broker Sign-In With Node.js User Agent via Tycoon 2FA
Malicious EdgeStepper iptables DNS Redirection for Adversary-in-the-Middle
Suspicious Tycoon 2FA Credential Exfiltration Fields
Suspicious Entra Sign-In to OfficeHome with axios User Agent
Suspicious Entra Sign-In Interrupt With High Aggregated Risk via AiTM DNS Hijacking (via azure)
Possible Adversary-in-the-Middle Proxy Login via Crafted URL Parameters
Suspicious AWS Console AiTM Phishing Kit API Endpoints
Pivot detection · T1557 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.