Malicious Google Ads being used to smuggle AWS phishing sites into search results

February 10, 2023

A new type of phishing attack has been discovered, in which malicious Google ads are used to insert AWS phishing sites into search results. Sentiel Labs’ security researchers made the discovery.

On January 30, 2023, Sentinel Labs analysts discovered the malicious search results. When searching for “aws,” the ads came in second, just behind Amazon’s own promoted search result.

The phishing attack works by redirecting users from a legitimate-looking Google ad to a bogus Amazon Web Services login page. The spoof login page is designed to look exactly like the real AWS login page, duping users into entering their login credentials. Once the attacker has the login credentials, he or she can access the victim’s AWS account and steal sensitive data.

The malicious Google ads reroute victims to a blogger website under the attacker’s control, which is a copy of a legitimate vegan food blog at “us1-eat-a-w-s.blogspot[.]com”. After being redirected to the fake blog, the user is prompted to log in using their AWS credentials. The attackers use this information to gain access to the victim’s AWS account, from which they can steal sensitive data and engage in other malicious activities.

When the user arrives at the bogus website, they are prompted to enter their AWS credentials by selecting whether they are a root or IAM user and then entering their email address and password. This information is used by the attackers to gain access to the victim’s AWS account and steal sensitive information.

The sources for this piece include an article in BleepingComputer.

Top Stories

Related Articles

March 27, 2026 Microsoft is updating GitHub Copilot to train on real-world developer interactions, expanding beyond public code datasets to more...

March 23, 2026 David Shipley, co-host of Cybersecurity today is covering RSAC for Tech Newsday and Cybersecurity Today.  SAN FRANCISCO more...

March 23, 2026 The U.S. Federal Communications Commission has banned the import of all new foreign-made consumer routers following a more...

March 19, 2026 The FBI has gone back to purchasing commercially available data, including Americans’ location histories, to support federal more...

Jim Love

Jim is an author and podcast host with over 40 years in technology.

Share:
Facebook
Twitter
LinkedIn