INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

AWS Keys Compromised in Amazon Bedrock Access Testing Vulnerability

| 2026-10-06 17:14 LOW MEDIUM DATA BREACH
Executive Summary
AI-generated
Attackers have targeted Amazon Bedrock, a cloud-based platform for AI model training and deployment, by exploiting exposed AWS keys. Multiple credential harvesting platforms, including KMON_NOC, were identified as testing stolen AWS keys for LLM capabilities, with scripts analyzed on VirusTotal demonstrating systematic testing across multiple regions targeting Anthropic Claude models specifically. The attackers validate credentials using GetCallerIdentity and test Bedrock access through ListFoundationModels and Converse API calls to assess credential value for resale in token-jacking markets. This represents an evolution in credential validation similar to historical patterns observed with AWS SES/SNS services, with the identified entities including Amazon Bedrock, AWS, LLM, and VirusTotal.
Technical Mitigations AI-generated
• Reset credentials and API keys that may have been exposed, and review access logs for the affected accounts or integrations.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected

Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.

923641••••••••••••••••••••••••••••••••••••••••••••••••••••••••••
c9335b••••••••••••••••••••••••••••••••••••••••••••••••••••••••••
191.93.•••.•••
196.177.•••.•••
46.100.•••.•••
83.194.•••.•••
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Target & Sectors
Global Scope retailretail
Incident Timeline
‎2026/10/06
Threat actors used multiple credential harvesting platforms to test stolen AWS keys for LLM capabilities on Anthropic Claude models.
organisation Amazon Bedrock
organisation AWS
organisation LLM
organisation VirusTotal
Intelligence Sources