Beyond valid credentials: How exposed AWS keys are tested for Amazon Bedrock access
Attackers who gain access to AWS credentials perform validation to determine their usefulness, particularly for Amazon Bedrock access. Multiple credential harvesting platforms, including KMON_NOC, have been identified that specifically test stolen AWS keys for LLM capabilities. These platforms validate credentials using GetCallerIdentity, then test Bedrock access through ListFoundationModels and Converse API calls. The validation process helps attackers assess credential value for resale in token-jacking markets, where stolen AI model access is sold below retail price. Scripts analyzed on VirusTotal demonstrate systematic testing across multiple regions, targeting Anthropic Claude models specifically, and enumerating promotional credits to assess financial value. This represents an evolution in credential validation similar to historical patterns observed with AWS SES/SNS services.
Pulse ID: 6ac52c8896a61ee777d4aee5
Pulse Link: https://otx.alienvault.com/pulse/6ac52c8896a61ee777d4aee5
Pulse Author: AlienVault
Created: 2026-10-06 17:14:48
Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Amazon #AWS #CredentialHarvesting #VirusTotal #OTX #AlienVault