TruffleNet turns stolen AWS keys into high-volume BEC scams
Attackers used TruffleHog to validate stolen AWS keys, probed SES quotas and then forged sending identities with compromised DKIM keys to power targeted BEC invoices that demanded large payments; they concealed activity across hundreds of cloud hosts to avoid reputation checks. Source: Fortinet
Read more: CyberSecBrief






