Target Industry
Indiscriminate, opportunistic targeting.
Overview
The threat group, JavaGhost, is misconfiguring Amazon Web Services (AWS) environments and using Amazon Simple Email Service (SES) and WorkMail to launch phishing campaigns. JavaGhost has been active since 2019, and initially focused on website defacements but shifted to phishing in 2022 for financial gain.
Impact
By leveraging compromised AWS environments, phishing emails are sent that appear to come from legitimate sources. The phishing campaigns can result in financial losses for both the targeted organisations and the individuals who fall victim to the scams. JavaGhost can create new Identity and Access Management (IAM) user accounts to access sensitive data, potentially leading to data breaches and the exposure of confidential information.
Exploitation
Threat actors exploit exposed AWS access keys which are stored in public .env files in insecure web applications. These keys allow them to send phishing emails via SES to bypass email security protections as the emails appear to originate from trusted services. The threat actors obfuscate their activities by using uncommon API calls which are not logged in CloudTrail, making it harder to trace their actions.
Containment, Mitigations & Remediations
To mitigate the threat posed by JavaGhost it is recommended to take the following steps:
- Enforce least privilege by ensuring IAM policies grant the minimum permissions necessary for users to perform their tasks
- Regularly rotate AWS access keys to limit the risk of long-term exposure
- Require multi-factor authentication (MFA) for all IAM users to add an extra layer of security
- Enable CloudTrail logging for SES, WorkMail, and IAM activities to detect unusual behaviour
- Prefer short-term access tokens over long-term access keys to reduce the risk of misuse
- Deploy SPF, DKIM, and DMARC to detect and prevent fraudulent emails
- Regularly audit IAM policies and permissions to identify and remediate any overly permissive configurations.
Threat Landscape
AWS has a diverse user base that includes both enterprise-scale customers and small to medium-sized businesses, making it a widely adopted cloud platform globally. JavaGhost poses a significant threat to system security by hiding malicious activities and maintaining persistent access to compromised systems.
Threat Groups
JavaGhost has been active since 2022. It is a sophisticated threat actor group known for executing persistent phishing campaigns using compromised AWS environments. The specific location of the JavaGhost threat actor group is not publicly known. It operates in a highly covert manner, making it challenging to pinpoint its exact base of operations.
Further Information













