How Attackers Test Stolen AWS Keys for Amazon Bedrock Access

Summary
Datadog researchers detail tools that validate AWS credentials for Bedrock access by enumerating models and attempting inference. They observed similar activity at 12 organizations and recommend investigating unexpected Bedrock API calls.
Key points
- KMON_NOC frontend code indicates the credential-harvesting platform checks AWS keys with STS GetCallerIdentity, separately identifies Bedrock access, and extracts Bedrock bearer tokens. Associated hosts were observed probing for credentials at more than 80 Datadog Cloud SIEM customers.
- Two Python scripts found on VirusTotal process credential lists, identify AWS principals, test Bedrock across regions, and retain successful credentials in plaintext.
- The scripts use ListFoundationModels and may enumerate inference profiles before testing model access with Converse or InvokeModel. One also checks promotional credits through the Billing API.
- In the last 30 days, Datadog observed similar behavior at 12 organizations. One case involved successful multi-region model enumeration followed by Converse calls that received AccessDenied responses for Anthropic models.
- Researchers could not establish a link between the analyzed script and the activity in their telemetry.
- Datadog recommends investigating unexpected Bedrock activity, especially from new sources or identities with no history of AI usage, and monitoring model discovery and invocation API calls.
Article Details
- Attack Vectors
- KMON_NOC scans and probes for AWS credentials. Its frontend code indicates that it distinguishes valid AWS keys from keys with Amazon Bedrock access, but the researchers did not observe its AWS API activity.
- Two analyzed Python scripts process AWS credential lists, identify the associated principals, enumerate Bedrock models across regions, and attempt low-cost model invocations. One can also check promotional credits.
- In separate telemetry, the researchers observed suspicious multi-region Bedrock model discovery and, in one case, attempted Converse calls for Anthropic models. They could not link that telemetry to the analyzed script.
- Defensive Notes
- Investigate unexpected Amazon Bedrock activity, especially from a new source or an identity with no history of AI usage.
- Monitor both Converse and InvokeModel for credential-validation or LLMjacking activity, and correlate multi-region model enumeration with subsequent invocation attempts.
- Use the listed IP addresses only alongside the described AWS activity to improve confidence; the researchers say the addresses include residential proxies, VPNs, and hosting providers.
Indicators of compromise
| Type | Indicator | Context |
|---|---|---|
| IPV4 | 103[.]148[.]197[.]54 | IP observed attempting the described AWS credential-validation pattern. |
| IPV4 | 103[.]160[.]185[.]100 | IP observed attempting the described AWS credential-validation pattern. |
| IPV4 | 108[.]168[.]65[.]226 | IP observed attempting the described AWS credential-validation pattern. |
| IPV4 | 109[.]146[.]93[.]39 | IP observed attempting the described AWS credential-validation pattern. |
| IPV4 | 112[.]78[.]151[.]90 | IP observed attempting the described AWS credential-validation pattern. |
| IPV4 | 115[.]138[.]247[.]83 | IP observed attempting the described AWS credential-validation pattern. |
| IPV4 | 116[.]106[.]179[.]94 | IP observed attempting the described AWS credential-validation pattern. |
| IPV4 | 128[.]116[.]206[.]252 | IP observed attempting the described AWS credential-validation pattern. |
| IPV4 | 137[.]103[.]56[.]107 | IP observed attempting the described AWS credential-validation pattern. |
| IPV4 | 138[.]199[.]15[.]176 | IP observed attempting the described AWS credential-validation pattern. |
| IPV4 | 138[.]94[.]168[.]132 | IP observed attempting the described AWS credential-validation pattern. |
| IPV4 | 146[.]70[.]173[.]170 | IP observed attempting the described AWS credential-validation pattern. |
| IPV4 | 151[.]243[.]18[.]111 | IP observed attempting the described AWS credential-validation pattern. |
| IPV4 | 154[.]119[.]213[.]63 | IP observed attempting the described AWS credential-validation pattern. |
| IPV4 | 157[.]100[.]141[.]65 | IP observed attempting the described AWS credential-validation pattern. |
| IPV4 | 172[.]56[.]122[.]32 | IP observed attempting the described AWS credential-validation pattern. |
| IPV4 | 173[.]249[.]254[.]173 | IP observed attempting the described AWS credential-validation pattern. |
| IPV4 | 173[.]92[.]116[.]211 | IP observed attempting the described AWS credential-validation pattern. |
| IPV4 | 181[.]115[.]172[.]90 | IP observed attempting the described AWS credential-validation pattern. |
| IPV4 | 181[.]51[.]32[.]38 | IP observed attempting the described AWS credential-validation pattern. |
| IPV4 | 186[.]154[.]182[.]44 | IP observed attempting the described AWS credential-validation pattern. |
| IPV4 | 190[.]56[.]117[.]218 | IP observed attempting the described AWS credential-validation pattern. |
| IPV4 | 191[.]93[.]177[.]69 | IP observed attempting the described AWS credential-validation pattern. |
| IPV4 | 192[.]74[.]128[.]184 | IP observed attempting the described AWS credential-validation pattern. |
| IPV4 | 194[.]36[.]27[.]53 | IP observed attempting the described AWS credential-validation pattern. |
| IPV4 | 196[.]177[.]214[.]142 | IP observed attempting the described AWS credential-validation pattern. |
| IPV4 | 200[.]151[.]53[.]165 | IP observed attempting the described AWS credential-validation pattern. |
| IPV4 | 206[.]206[.]119[.]201 | IP observed attempting the described AWS credential-validation pattern. |
| IPV4 | 213[.]186[.]157[.]53 | IP observed attempting the described AWS credential-validation pattern. |
| IPV4 | 216[.]126[.]227[.]187 | IP observed attempting the described AWS credential-validation pattern. |
| IPV4 | 45[.]11[.]61[.]22 | IP observed attempting the described AWS credential-validation pattern. |
| IPV4 | 46[.]100[.]30[.]188 | IP observed attempting the described AWS credential-validation pattern. |
| IPV4 | 47[.]230[.]250[.]253 | IP observed attempting the described AWS credential-validation pattern. |
| IPV4 | 50[.]82[.]6[.]249 | IP observed attempting the described AWS credential-validation pattern. |
| IPV4 | 51[.]15[.]192[.]215 | IP observed attempting the described AWS credential-validation pattern. |
| IPV4 | 59[.]92[.]240[.]165 | IP observed attempting the described AWS credential-validation pattern. |
| IPV4 | 69[.]250[.]15[.]174 | IP observed attempting the described AWS credential-validation pattern. |
| IPV4 | 71[.]76[.]4[.]45 | IP observed attempting the described AWS credential-validation pattern. |
| IPV4 | 72[.]235[.]197[.]91 | IP observed attempting the described AWS credential-validation pattern. |
| IPV4 | 78[.]109[.]78[.]211 | IP observed attempting the described AWS credential-validation pattern. |
| IPV4 | 79[.]117[.]129[.]254 | IP observed attempting the described AWS credential-validation pattern. |
| IPV4 | 82[.]86[.]130[.]180 | IP observed attempting the described AWS credential-validation pattern. |
| IPV4 | 83[.]194[.]172[.]248 | IP observed attempting the described AWS credential-validation pattern. |
| IPV4 | 84[.]50[.]134[.]231 | IP observed attempting the described AWS credential-validation pattern. |
| IPV4 | 85[.]137[.]52[.]59 | IP observed attempting the described AWS credential-validation pattern. |
| IPV4 | 85[.]137[.]53[.]173 | IP observed attempting the described AWS credential-validation pattern. |
| IPV4 | 85[.]253[.]221[.]206 | IP observed attempting the described AWS credential-validation pattern. |
| IPV4 | 87[.]58[.]197[.]196 | IP observed attempting the described AWS credential-validation pattern. |
| IPV4 | 87[.]58[.]197[.]199 | IP observed attempting the described AWS credential-validation pattern. |
| IPV4 | 88[.]167[.]240[.]60 | IP observed attempting the described AWS credential-validation pattern. |
| IPV4 | 89[.]249[.]72[.]22 | IP observed attempting the described AWS credential-validation pattern. |
| IPV4 | 92[.]144[.]3[.]108 | IP observed attempting the described AWS credential-validation pattern. |
| IPV4 | 92[.]216[.]157[.]153 | IP observed attempting the described AWS credential-validation pattern. |
| IPV4 | 93[.]118[.]107[.]1 | IP observed attempting the described AWS credential-validation pattern. |
| IPV4 | 94[.]154[.]46[.]242 | IP observed attempting the described AWS credential-validation pattern. |
| IPV4 | 94[.]154[.]46[.]243 | IP observed attempting the described AWS credential-validation pattern. |
| IPV4 | 94[.]154[.]46[.]245 | IP observed attempting the described AWS credential-validation pattern. |
| IPV4 | 94[.]154[.]46[.]246 | IP observed attempting the described AWS credential-validation pattern. |
| IPV4 | 94[.]154[.]46[.]247 | IP observed attempting the described AWS credential-validation pattern. |
| IPV4 | 94[.]154[.]46[.]248 | IP observed attempting the described AWS credential-validation pattern. |
| IPV4 | 94[.]154[.]46[.]249 | IP observed attempting the described AWS credential-validation pattern. |
| IPV4 | 94[.]154[.]46[.]250 | IP observed attempting the described AWS credential-validation pattern. |
| IPV4 | 95[.]216[.]34[.]254 | IP observed attempting the described AWS credential-validation pattern. |
| IPV4 | 98[.]44[.]224[.]55 | IP observed attempting the described AWS credential-validation pattern. |
| SHA256 | 923641364ef0ce3a6f1d944890244082b8c7f29c9600c0433b2a0ca9822c0608 | Hash of an analyzed Python script that validates AWS credentials, tests Bedrock access, and can enumerate promotional credits. |
| SHA256 | c9335bb8a21bd2c568d03b040fb86a0e72145691e54a33495ee0cfaac55835dc | Hash of an analyzed Python script that validates AWS credentials and tests Bedrock access. |
MITRE ATT&CK
T1078.004 · Cloud AccountsThe analyzed scripts test AWS credential lists and use working cloud credentials to call AWS identity and Amazon Bedrock APIs.T1087.004 · Cloud AccountThe analyzed scripts call STS GetCallerIdentity to retrieve the AWS account ID and principal identity associated with each credential.T1526 · Cloud Service DiscoveryThe analyzed scripts call ListFoundationModels and, when invocation testing is enabled, ListInferenceProfiles across regions to discover accessible Amazon Bedrock models and profiles.
Vendors
AnthropicTo obtain Bedrock credentials, the platforms first called GetCallerIdentity, then listed the available foundation models by using ListFoundationModels and tried InvokeModel multiple times on different Anthropic models.AWSFor years, this has been true for the AWS SES/SNS services.DatadogWe have identified hosts associated with this platform scanning and probing for credentials in over 80 Datadog Cloud SIEM customers.
Products
Amazon BedrockWe've observed several tools and platforms that validate stolen AWS credentials by testing not only whether they are active but also whether they can discover and invoke Amazon Bedrock models.Claude# We deliberately do NOT send 'temperature' - newer Claude models (Opus 4.7+,Cloud SIEMWe have identified hosts associated with this platform scanning and probing for credentials in over 80 Datadog Cloud SIEM customers.