“Legitimate” phishing: how attackers weaponize Amazon SES to bypass email security
2026-05-04T20:52:03Z•b687d76844a41f23a7c0bcd7ea350f44308829c4b02838317313f13ca5490f68
ABCDoorAmazon SESApp Store malwareBECClipBankerCrystalXFakeWalletICSJanelaRATMaaSPhantomRPCRATRPC vulnerabilitySilver FoxValleyRATWindowsclipboard malwarecryptocurrency theftemail securityiOSindustrial control systemsmobile stealerphishingprivilege escalationsupply chain attack','LiteLLM
What happened
Feed of Kaspersky Securelist analyses (Mar–May 2026) covering multiple active threats and research: weaponized Amazon SES phishing and BEC campaigns; Silver Fox targeting Russia and India using tax-notification lures to deliver ValleyRAT and a new ABCDoor backdoor; PhantomRPC — a newly reported Windows RPC privilege‑escalation technique; FakeWallet iOS crypto‑stealer apps found in the App Store; Q4 2025 industrial automation (ICS) threat trends; JanelaRAT financial malware in Latin America; ClipBanker clipboard‑address replacement delivered via a trojanized Proxifier; CrystalX RAT (MaaS) with偷
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- kaspersky_securelist
- Record identifier
- b687d76844a41f23a7c0bcd7ea350f44308829c4b02838317313f13ca5490f68
- Enrichment time
- 2026-05-04T20:52:03Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.