{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/ses/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Simple Email Service (SES)"],"_cs_severities":["medium"],"_cs_tags":["cloud","aws","ses","resource-development","defense-evasion"],"_cs_type":"advisory","_cs_vendors":["Amazon"],"content_html":"\u003cp\u003eAdversaries who obtain unauthorized AWS credentials with SES permissions often abuse the service to send bulk unsolicited email using the victim account's reputation and sending quota. To minimize the forensic footprint, attackers employ a specific 'verify-use-delete' technique. This involves programmatically verifying a domain or email identity they control, utilizing the account to send malicious traffic, and subsequently deleting the identity within a short timeframe (typically under 30 minutes). This deletion removes the evidence from the account's verified identity list, complicating post-incident forensic review and attribution. Defenders must monitor CloudTrail management events to identify this rapid lifecycle of SES identities.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker gains unauthorized access to AWS credentials with SES write permissions (e.g., via leaked access keys or compromised IAM roles).\u003c/li\u003e\n\u003cli\u003eAttacker calls \u003ccode\u003eVerifyDomainIdentity\u003c/code\u003e or \u003ccode\u003eVerifyEmailIdentity\u003c/code\u003e to register an attacker-controlled domain or email address within the victim's AWS environment.\u003c/li\u003e\n\u003cli\u003eAttacker completes the domain verification process (e.g., via DNS record validation).\u003c/li\u003e\n\u003cli\u003eAttacker uses the \u003ccode\u003eSendEmail\u003c/code\u003e or \u003ccode\u003eSendRawEmail\u003c/code\u003e API actions to dispatch phishing or spam campaigns using the victim's reputation.\u003c/li\u003e\n\u003cli\u003eAttacker calls \u003ccode\u003eDeleteIdentity\u003c/code\u003e to remove the domain or email address from the account.\u003c/li\u003e\n\u003cli\u003eVictim's list of verified SES identities no longer shows the attacker's domain, effectively hiding the configuration used for the malicious campaign.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful abuse of AWS SES results in the degradation of the victim account's email sender reputation, potential blacklisting by major email providers, and utilization of the organization's email sending quotas for malicious activities. Furthermore, the rapid deletion of identities hinders security teams' ability to perform root cause analysis and attribute the campaign to a specific domain or sender, potentially leading to persistent or recurring abuse.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImplement the detection logic provided in this brief to alert on the verify-then-delete pattern observed in CloudTrail logs.\u003c/li\u003e\n\u003cli\u003eRestrict the \u003ccode\u003eses:VerifyEmailIdentity\u003c/code\u003e, \u003ccode\u003eses:VerifyDomainIdentity\u003c/code\u003e, and \u003ccode\u003eses:DeleteIdentity\u003c/code\u003e IAM actions to a dedicated SES-management role using Least Privilege principles.\u003c/li\u003e\n\u003cli\u003eEnable SES sending quotas and configured alerts to identify anomalous traffic spikes in real time.\u003c/li\u003e\n\u003cli\u003eReview all SES management events if a sudden drop in account sender reputation or an abuse complaint from an external provider is identified.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-31T17:52:25Z","date_published":"2026-08-31T17:52:25Z","id":"https://feed.craftedsignal.io/briefs/2026-08-aws-ses-abuse/","summary":"Adversaries with unauthorized access to AWS Simple Email Service (SES) credentials may verify an attacker-controlled identity, send phishing or spam emails, and promptly delete the identity to evade detection and attribution.","title":"Detection of AWS SES Identity Verify-Use-Delete Abusive Pattern","url":"https://feed.craftedsignal.io/briefs/2026-08-aws-ses-abuse/"}],"language":"en","title":"CraftedSignal Threat Feed - Ses","version":"https://jsonfeed.org/version/1.1"}