Sublime Security medium experimental mql

Credential phishing: AWS Lambda URL with recipient targeting

Detects messages containing AWS Lambda URLs with the recipient's email address embedded in the fragment, indicating potential abuse of AWS Lambda services for targeted malicious activities.

View Source

Detection Logic

type.inbound
and recipients.to[0].email.domain.sld == sender.email.local_part
and any(body.links,
        strings.icontains(.href_url.domain.domain, "lambda-url")
        and strings.icontains(.href_url.fragment, recipients.to[0].email.email)
)

Field Validations

Loading…

Comments (0)

Loading comments...