“Legitimate” phishing: how attackers weaponize Amazon SES to bypass email security

2026-05-04T20:52:03Zb687d76844a41f23a7c0bcd7ea350f44308829c4b02838317313f13ca5490f68
ABCDoorAmazon SESApp Store malwareBECClipBankerCrystalXFakeWalletICSJanelaRATMaaSPhantomRPCRATRPC vulnerabilitySilver FoxValleyRATWindowsclipboard malwarecryptocurrency theftemail securityiOSindustrial control systemsmobile stealerphishingprivilege escalationsupply chain attack','LiteLLM

What happened

Feed of Kaspersky Securelist analyses (Mar–May 2026) covering multiple active threats and research: weaponized Amazon SES phishing and BEC campaigns; Silver Fox targeting Russia and India using tax-notification lures to deliver ValleyRAT and a new ABCDoor backdoor; PhantomRPC — a newly reported Windows RPC privilege‑escalation technique; FakeWallet iOS crypto‑stealer apps found in the App Store; Q4 2025 industrial automation (ICS) threat trends; JanelaRAT financial malware in Latin America; ClipBanker clipboard‑address replacement delivered via a trojanized Proxifier; CrystalX RAT (MaaS) with偷

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
kaspersky_securelist
Record identifier
b687d76844a41f23a7c0bcd7ea350f44308829c4b02838317313f13ca5490f68
Enrichment time
2026-05-04T20:52:03Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · “Legitimate” phishing: how attackers weaponize Amazon SES to bypass email security · Baitaphish