Suspicious AWS Console Phishing MFA Relay Endpoints

PremiumReviewedSigma · Medium · v1
Category
proxy
Author
HuntRule
Published
2026-09-15
Updated
2026-09-15

ATT&CK techniques

Initial Access → Cred Access
  1. Recon

  2. Resource Dev

  3. Execution

  4. Discovery

  5. Lateral Movement

  6. Collection

  7. C2

  8. Exfiltration

  9. Impact

What it detects

This rule detects requests to the MFA relay endpoints of the AWS console phishing kit that intercept second-factor codes delivered by email, SMS, or authenticator app. The kit prompts victims for their one-time codes and forwards them so the operator can complete authentication in real time. Traffic to these email, sms, and gauth relay paths on a login-lookalike host indicates active MFA interception.

Related detections9 linkedT1078.004 — drag to rearrange
Azure Sign-in Logs: MFA Denied Based on Authentication Requirement
Azure Sign-in Log MFA Interrupted via Strong Auth Failures
Suspicious AWS AiTM Phishing Kit Endpoint Access via Proxy
Suspicious AiTM Session Cookie Exfiltration to log_cookie Endpoint
Suspicious Azure AD MFA Fatigue Repeated Push Denials
Possible SES Sending Configuration Enumeration via CloudTrail
Suspicious AWS Role Assumption via Cognito Web Identity
Suspicious Google Cloud Function Create or Update Triggering Build
Possible Credential Stuffing Blocked by Conditional Access in Microsoft 365
Suspicious AWS Console Phishing MFA Relay Endpoints
Pivot detection · T1078.004 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.