INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
AWS Keys Compromised in Amazon Bedrock Access Testing Vulnerability
| 2026-10-06 17:14 DATA BREACH
Executive Summary
AI-generated
Attackers have targeted Amazon Bedrock, a cloud-based platform for AI model training and deployment, by exploiting exposed AWS keys. Multiple credential harvesting platforms, including KMON_NOC, were identified as testing stolen AWS keys for LLM capabilities, with scripts analyzed on VirusTotal demonstrating systematic testing across multiple regions targeting Anthropic Claude models specifically. The attackers validate credentials using GetCallerIdentity and test Bedrock access through ListFoundationModels and Converse API calls to assess credential value for resale in token-jacking markets. This represents an evolution in credential validation similar to historical patterns observed with AWS SES/SNS services, with the identified entities including Amazon Bedrock, AWS, LLM, and VirusTotal.
Technical Mitigations AI-generated
• Reset credentials and API keys that may have been exposed, and review access logs for the affected accounts or integrations.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected
Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.
923641••••••••••••••••••••••••••••••••••••••••••••••••••••••••••
c9335b••••••••••••••••••••••••••••••••••••••••••••••••••••••••••
191.93.•••.•••
196.177.•••.•••
46.100.•••.•••
83.194.•••.•••
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Target & Sectors
Global Scope
Incident Timeline
Intelligence Sources
AlienVault OTX
2026-10-06