Target Industry

Indiscriminate, opportunistic targeting.

Overview

The threat group, JavaGhost, is misconfiguring Amazon Web Services (AWS) environments and using Amazon Simple Email Service (SES) and WorkMail to launch phishing campaigns. JavaGhost has been active since 2019, and initially focused on website defacements but shifted to phishing in 2022 for financial gain. 

Impact

By leveraging compromised AWS environments, phishing emails are sent that appear to come from legitimate sources. The phishing campaigns can result in financial losses for both the targeted organisations and the individuals who fall victim to the scams. JavaGhost can create new Identity and Access Management (IAM) user accounts to access sensitive data, potentially leading to data breaches and the exposure of confidential information.  

Exploitation

Threat actors exploit exposed AWS access keys which are stored in public .env files in insecure web applications. These keys allow them to send phishing emails via SES to bypass email security protections as the emails appear to originate from trusted services. The threat actors obfuscate their activities by using uncommon API calls which are not logged in CloudTrail, making it harder to trace their actions. 

Containment, Mitigations & Remediations

To mitigate the threat posed by JavaGhost it is recommended to take the following steps: 

  • Enforce least privilege by ensuring IAM policies grant the minimum permissions necessary for users to perform their tasks 
  • Regularly rotate AWS access keys to limit the risk of long-term exposure 
  • Require multi-factor authentication (MFA) for all IAM users to add an extra layer of security 
  • Enable CloudTrail logging for SES, WorkMail, and IAM activities to detect unusual behaviour 
  • Prefer short-term access tokens over long-term access keys to reduce the risk of misuse 
  • Deploy SPF, DKIM, and DMARC to detect and prevent fraudulent emails 
  • Regularly audit IAM policies and permissions to identify and remediate any overly permissive configurations. 

Threat Landscape

AWS has a diverse user base that includes both enterprise-scale customers and small to medium-sized businesses, making it a widely adopted cloud platform globally. JavaGhost poses a significant threat to system security by hiding malicious activities and maintaining persistent access to compromised systems. 

Threat Groups

JavaGhost has been active since 2022. It is a sophisticated threat actor group known for executing persistent phishing campaigns using compromised AWS environments. The specific location of the JavaGhost threat actor group is not publicly known. It operates in a highly covert manner, making it challenging to pinpoint its exact base of operations. 

Further Information

Further Threat Intelligence from Quorum Cyber

Headquarters

Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ

FLORIDA, USA Office

501 E Kennedy Blvd.
STE 1400
Tampa FL 33602

Ontario, Canada Office

1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7

Contact Us
Address

Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ

501 E Kennedy Blvd
STE 1400
Tampa FL 33602

1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7

HEADQUARTERS
Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ



FLORIDA, USA OFFICE
501 E Kennedy Blvd.
STE 1400
Tampa FL 33602


ONTARIO, CANADA OFFICE
1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7


Legal

Privacy Preference Center

Skip to content