I'm seeing renewed abuse of AWS Amplify service (amplifyapp[.]com) as the lure URL in phishing/malware emails. I want to alert the community, if you're not using Amazon Amplify in your environment, it’s probably one to block.
Amazon says “Accelerate your full-stack web and mobile app development with AWS Amplify. Easy to start, easy to scale. No cloud expertise needed." It’s perfect for your budding threat actor, and since there's a free use tier, what more could they ask for! #threatintel