AWS messaging services carry mail and application events, and each one is useful to an attacker holding the right permission. SES sends mail as the victim, borrowing a domain's established sending reputation for phishing. SNS and SQS move application messages, so topic and queue access means reading the data flowing through, injecting forged events, or dropping messages a system depends on.
What folds in here#
- SES: sending phishing and spoofed mail from verified identities, and reading the account's sending quota and verified domains.
- SNS: publishing to topics, subscribing to capture notifications, and exfiltrating through a subscription.
- SQS: reading, injecting, and deleting messages in a queue exposed by its resource policy.