Week in review: AiTM phishing kit used to hijack AWS accounts, year-long malware campaign targets HR

2026-03-15T14:51:52Zb982d39b952afd7d02666058a362f025e91491cb58283c64c09602a3285ea6b9
AI coding agentsATOAWSAiTMCSAMEU policyGenAI securityHR-targetingMFA weaknessesSSESocksEscortaccount takeovercredential stuffingcryptocurrency seizuredevice fingerprintingdevice intelligencefraudlaw enforcement takedownmalwarephishingproxy networksoftware security

What happened

Weekly roundup: reports show an AiTM phishing kit was used to hijack AWS accounts and a year-long malware campaign targeted HR teams, highlighting active account takeover (ATO) and credential-theft operations. Law enforcement disrupted the SocksEscort residential proxy network, seizing domains, servers and ~$3.5M in cryptocurrency linked to large-scale fraud; Eurojust/German authorities also arrested suspects in a €1M online fraud scheme. Industry responses and product news include Accertify’s Attack State for detecting credential stuffing/ATO, BioCatch DeviceIQ for device intelligence, Red A​

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
helpnetsecurity
Record identifier
b982d39b952afd7d02666058a362f025e91491cb58283c64c09602a3285ea6b9
Enrichment time
2026-03-15T14:51:52Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.