Bucket-in-Path: How Phishers Launder Through AWS S3 and SES
Bucket-in-Path: How Phishers Launder Through AWS S3 and SES
Over a 30-day window, we mapped independent email operators using Amazon S3, SES, and awstrack.me redirectors as a shared phishing-delivery substrate. These operators did not need to own a server, buy a TLS certificate, or register anything more durable than a throwaway sending domain. Instead, they rented Amazon's trust. Otherwise unrelated credential-phishing and brand-impersonation waves converged on the same AWS-owned hostnames and relied on a property those hostnames share: filters tend to trust the parent domain without evaluating the individual bucket, account, or redirector beneath it.
Key Takeaways
- Multiple independent email operators use the same AWS-owned services (S3, SES, CloudFront, API Gateway) as a shared, trusted delivery layer.
- Path-style S3 addressing places every campaign on one shared apex host, defeating per-bucket URL reputation by design.
- SES click-tracking rewrites every link as an AWS-signed redirector, so the scam URL does not appear in the message body and the trusted first hop launders the destination.
- The eight-character SES account prefix in each redirector subdomain persists through AWS-region rotation and provides a durable per-operator correlator.
- Burner sending domains cluster on budget registrars, using invented, dictionary-adjacent names and one-year registrations.
Background
Amazon S3 is an object-storage service, and any bucket can serve static HTML, CSS, and JavaScript directly to a browser over HTTPS from an AWS-owned endpoint. That makes it attractive to an operator staging a credential-harvest page. The page comes from a genuine amazonaws.com host behind a valid AWS-issued certificate, so the padlock, certificate chain, and parent domain all appear to belong to Amazon. Many URL-reputation systems and secure email gateways allow amazonaws.com by policy instead of evaluating the bucket beneath it.
The same trust model applies across the rest of the stack. Amazon SES is AWS's bulk and transactional mail service. A sender that delivers mail through SES, whether by signing up directly or using a compromised or reseller sub-tenant account, inherits AWS sending-IP reputation and clean authentication that a burner VPS mailer would never pass. With SES open and click tracking enabled, SES rewrites every link in the outbound message as an AWS-owned redirector under awstrack.me, which forwards to the actual destination. CloudFront, Amazon's CDN, can place another reputable cloudfront.net layer in front of an origin bucket. Amazon API Gateway provides serverless HTTP endpoints under execute-api.<region>.amazonaws.com, allowing a landing page to POST stolen credentials to a collection backend that is also a trusted AWS host, with no attacker-owned server to seize. We also observed a commerce-platform ESP, ShopLine, originating lure mail through reseller or sub-tenant sending.
Bucket-hosted phishing and trusted-cloud-redirector laundering are established technique families. Cofense documented S3 bucket phishing, SES compromise, and awstrack.me click-tracking redirectors that hid the final URL in early 2026. Cloudflare has reported the same trust-laundering mechanism in commercial link-wrapping services, while Unit 42 has covered SES-style sending abuse through compromised cloud credentials. Our survey adds horizontal scale, an addressing distinction that changes how defenders counter S3 abuse, and a durable correlator for SES operators.
Discovery and Infrastructure
We began with a cross-channel inventory of every AWS-owned host found in scam traffic. We recorded the resolved hosts rather than the links as written because the operator-facing link is often a sending domain or shortener; the AWS host appears only after resolution. We then grouped the resolved hosts and separated shared-apex noise from per-bucket signal to produce the map below.
| AWS surface | Role in the chain | Observed footprint (30d) |
|---|---|---|
| S3 (vhost-style) | Bucket-hosted landing pages | 369 distinct buckets |
| S3 (path-style) | Bucket-in-path landing pages | shared apex, bucket in URL path |
SES / awstrack.me |
Click-tracking redirector to the landing | 222 subdomains, 18+ operator IDs |
| CloudFront | CDN-fronted landing origin | minor surface |
| API Gateway | Serverless credential-collection backend | emerging surface |
The sending layer behind this infrastructure consists of burner domains, dominated by a parcel-status lure ring that runs more than 240 sending domains through dedicated SES accounts. The brand-impersonation waves hosted on S3 used Costco, T-Mobile, TruGreen, and Renewal by Andersen lures. Each was staged as a static bucket page rather than on operator-owned hosting.
How It Works
The representative chain is short and hosted almost entirely on AWS. A throwaway sending domain sends the lure through SES. SES rewrites the call-to-action as an AWS-signed awstrack.me first hop, leaving only a trusted Amazon link in the message body seen by a scanner. The redirector returns a 302 to an S3-hosted landing page. That page may use vhost-style addressing, but increasingly uses path-style addressing to keep the bucket name out of the hostname; CloudFront occasionally sits in front of it. The page's credential form posts to an API Gateway endpoint. Neither the victim nor the filter sees an attacker-owned domain in a position where reputation would have an effect.
Sample Lures
The two samples below represent the two dominant email surfaces. Both contain only attacker-side content; we removed recipient data and defanged every operator hostname.
Parcel-status lure feeding the SES redirector layer:
From: "" <support@ceremonye[.]com>
Subject: [Important] Your parcel's status has updated
CTA (first hop): http[:]//<8char>.r.<region>.awstrack[.]me/L0/... -> bucket-hosted landing
Auto-insurance lure staged path-style on S3, with unrelated filler text used as a hash-buster:
From: "Coverage-Update" <bikini.chateauyt@jealousy.dimensiongravity[.]world>
Subject: Is It Time to Lower Your Car Insurance Rate?
Body (excerpt): Stand with the Dons this Saturday | Kilmarnock (H) ... [unrelated hash-busting filler]
CTA: http[:]//s3[.]amazonaws[.]com/pghbzw9qsbtn/... (bucket in path, not in host)
The second call-to-action captures the entire technique in one line. The bucket pghbzw9qsbtn is a twelve-character random string, but because it appears in the URL path, a per-host reputation lookup sees only the neutral shared s3.amazonaws.com apex.
Technical Analysis
S3 Addressing and Bucket-in-Path Laundering
S3 buckets are reachable in two ways, and the choice creates a defensive fork. Vhost-style addressing places the bucket name in the hostname, <bucket>.s3.<region>.amazonaws.com. Each bucket therefore has its own fully-qualified name, which a reputation index can score and block independently. We observed 369 distinct vhost-style buckets during the window. Path-style addressing places the bucket name in the URL path, s3.amazonaws.com/<bucket>/..., putting every campaign on one shared apex host. A per-host reputation system sees only that neutral shared endpoint. Blocking one path-style campaign at the host level would block all S3 path-style traffic, while per-bucket badness never accumulates against anything blockable. The choice of path-style addressing is a deliberate laundering technique against per-bucket reputation, and we observed operators using it at scale.
SES Redirectors and the Operator-ID Correlator
When tracking is enabled, SES rewrites links as awstrack.me URLs. This gives the operator an AWS-signed first hop and keeps the actual landing URL out of the message body. The redirector subdomain follows a stable pattern: <8char>.r.<region>.awstrack.me. Operators rotate the region token, resetting any reputation tied to the full subdomain. The eight-character prefix does not rotate. Because it is scoped to the SES account, it persists through region rotation and links otherwise separate sending waves to one account. During the window, we counted 222 distinct redirector subdomains that resolved to 18 or more durable eight-character operator identities. Using the prefix rather than the full host provides a direct way to outlast the rotation.
| Field | Position | Stability | Defender use |
|---|---|---|---|
| 8-char prefix | <8char>.r.<region>.awstrack[.]me |
survives region rotation | durable per-account correlator |
| region token | .r.<region>. |
rotates | not a stable key |
/L0/ redirect path |
URL path | per-link | follow to reveal the final landing URL |
Bucket-Naming Grammar
Bucket names fall into a few families, and each family provides a fingerprint. The dominant family uses a twelve-character random lowercase alphanumeric string generated automatically for each wave. A secondary family uses a sixteen-character hex string, which is the default format of some tooling. A niche family consists of long, consonant-heavy strings between nineteen and twenty-seven characters, distinct enough to indicate a separate toolset. A fourth, opportunistic family includes a brand or reward keyword for targeted lures.
| Family | Pattern | Notes | Prevalence |
|---|---|---|---|
| Random alphanumeric | [a-z0-9]{12} |
auto-generated per wave | dominant |
| Hex | [0-9a-f]{16} |
tooling default | secondary |
| Consonant string | consonant-heavy, length 19-27 | distinct toolset fingerprint | niche |
| Brand-keyword | <brand/keyword>-* |
targeted-lure buckets | opportunistic |
Registration Cohorts
The sending domains no longer appear random once we examine the WHOIS data. They cluster around a pair of budget registrars, Alibaba Cloud / HiChina and Xin Net Technology, with one-year registration terms and no renewal history. Their names are invented but dictionary-adjacent. Operators either append a letter to a real word (independent becomes independentl[.]com, ceremony becomes ceremonye[.]com, gorgeous becomes gorgeousof[.]com) or transpose letters within one (sculpture becomes sculptiure[.]com, automation becomes autobymation[.]com). The names are human-plausible, cheap to register, and have no prior reputation. Registration dates run from 2023 into late 2025 across the same registrar families, indicating a persistent operator population that re-provisions on a cadence rather than a single burst.
| Domain | Registrar | Registered | Term |
|---|---|---|---|
ceremonye[.]com |
Alibaba / HiChina | 2023-02-06 | 1 year |
independentl[.]com |
Alibaba / HiChina | 2023-02-06 | 1 year |
sculptiure[.]com |
Alibaba / HiChina | 2023-05-25 | 1 year |
rcleaimnate[.]com |
Alibaba / HiChina | 2023-08-16 | 1 year |
duplicatem[.]com |
Alibaba / HiChina | 2024-08-24 | 1 year |
gorgeousof[.]com |
Alibaba / HiChina | 2025-04-28 | 1 year |
autobymation[.]com |
Alibaba / HiChina | 2025-12-01 | 1 year |
24hservice[.]vip |
Communigal | 2025-06-02 | 1 year |
lastupper[.]com |
Xin Net | 2025-08 | 1 year |
reachbound[.]com |
Xin Net | 2025-08 | 1 year |
What Ties Independent Operators Together
Shared infrastructure does not imply a single actor. These waves use the same AWS trust plane, adopt the same path-style laundering, and obtain sending domains from the same budget-registrar cohort using the same invented-word grammar. That overlap may reflect convergent tradecraft as much as shared ownership. The pivots that reliably connect traffic to one account are narrower: the eight-character SES operator prefix across region-rotated subdomains, plus any reuse of a specific bucket or backend endpoint. Over the window, the visible shift was toward heavier evasion: more path-style S3 to blunt per-bucket indexing, more CloudFront fronting, and API Gateway backends that leave no attacker host to take down.
Detection Observations
The useful signals for separating this traffic from legitimate AWS use are structural rather than content-based.
- A message with an
awstrack.meredirector as its only visible link, sent from a domain with no brand equity and a recent one-year registration, presents a strong pairing even before anyone follows the redirect. - Path-style
s3.amazonaws.com/<bucket>/call-to-action URLs behave differently from vhost-style URLs under host reputation. Defenders should extract and track the bucket name in the path rather than the shared apex. - The eight-character SES prefix persists through region rotation. Grouping redirector traffic by that prefix links an operator whose traffic subdomain-level tracking would otherwise fragment.
- Bucket names fall into a small set of generation grammars. An unfamiliar bucket matching the twelve-character random or long-consonant families is therefore a reasonable prioritization signal.
- AWS-owned apex hosts (
amazonaws.com,awstrack.me,cloudfront.net,execute-api.<region>.amazonaws.com) are shared multi-tenant infrastructure and should never be blocked at the apex. The actionable unit is the bucket, operator prefix, or sending domain.
Mitigation and Guidance
- Follow
awstrack.meand other trusted-first-hop redirectors to the final destination before adjudicating a link because the message body will not contain the landing URL. - Extract the bucket name from path-style S3 URLs and track reputation per bucket-in-path because the host alone contains no per-campaign signal.
- Correlate SES-originated scam traffic by the eight-character redirector prefix rather than the full subdomain, preventing region rotation from fragmenting an operator.
- Weight sending domains according to registrar and registration age. A one-year registration through a budget registrar, combined with an invented dictionary-adjacent name, is a cheap, high-yield prioritization feature.
- Keep AWS-owned apex hosts off host-level blocklists and apply any verdict to the bucket, prefix, or sending domain.
Indicators of Compromise
The following is a representative, defanged subset of confirmed operator infrastructure. The AWS-owned service hosts abused by these campaigns (amazonaws.com, awstrack.me, cloudfront.net, execute-api.<region>.amazonaws.com) are shared multi-tenant infrastructure, so we deliberately excluded them. They are not indicators.
Senders
| Value | Role | Notes |
|---|---|---|
bikini.chateauyt@jealousy.dimensiongravity[.]world |
Sender | Auto-insurance lure staged path-style on S3 |
Domains
| Value | Role | Notes |
|---|---|---|
ceremonye[.]com |
Sender | Parcel-status lure via SES redirector |
independentl[.]com |
Sender | Parcel-status lure via SES redirector |
reachbound[.]com |
Sender | Parcel-status lure via SES redirector |
sculptiure[.]com |
Sender | Budget-registrar burner, invented SLD |
rcleaimnate[.]com |
Sender | Budget-registrar burner, invented SLD |
duplicatem[.]com |
Sender | Budget-registrar burner, invented SLD |
gorgeousof[.]com |
Sender | Budget-registrar burner, invented SLD |
autobymation[.]com |
Sender | Budget-registrar burner, invented SLD |
lastupper[.]com |
Sender | Budget-registrar burner, invented SLD |
24hservice[.]vip |
Sender | Budget-registrar burner |
epacknetic[.]live |
Sender / CTA | Fake e-commerce shipping lure |
MITRE Fight Fraud Framework Mapping
These TTPs map to the MITRE Fight Fraud Framework (F3) v1.1, https://ctid.mitre.org/fraud. Six of F3's eight tactics are inherited from enterprise ATT&CK, and F3 reuses ATT&CK T#### identifiers for inherited techniques. The table therefore lists F3 tactic and technique names and cross-references ATT&CK technique IDs for the infrastructure layer.
| F3 tactic | Technique (name) | ATT&CK cross-reference |
|---|---|---|
| Resource Development | Acquire Infrastructure (buckets, sending domains) | T1583, T1583.006 Web Services |
| Resource Development | Establish or Compromise Accounts (SES, ESP sub-tenants) | T1585 |
| Initial Access | Phishing Message | T1566 |
| Stealth | Trusted-Platform Hosting and Redirector Laundering | T1608.005 Link Target, T1656 Impersonation |
Conclusion
Across this survey, the operators had to build very little. Their durable assets are the AWS account and the tradecraft, not the infrastructure. For that reason, the correlators that persist are the SES account prefix and the bucket-in-path name, not any hostname. Region rotation and path-style addressing follow the same logic: both provide low-cost evasion and shift the burden to defenders willing to look beyond the trusted parent domain. The operator prefix and the bucket in the path are the two units worth tracking. Everything above them is shared ground rented by the operator.
Related research
The Supplement SMS Kit That Borrows Real Business Identities
Since April 2026, one operation has run 26 supplement storefront domains by text message, most carrying the legal identity of a real registered business.
How a Government-Impersonation Smishing Kit Signs Its Own Registration Batches
A smishing kit impersonating toll agencies, tax offices and national police stamped the registration date into its own WHOIS records.
One Lure, Four Operators: Ad Tracking Strings as Fingerprints
Four separate operators ran the same fake TradingView desktop-app ads on Facebook for nine months, and one query-string key was all that told them apart.