Datadog Tracks AI-Assisted Credential-Harvesting Platforms and AWS Abuse

Summary
Datadog researchers analyzed two exposed credential-harvesting dashboards that validate stolen secrets and support post-exploitation actions, and observed attempts to use compromised AWS credentials to probe and access Amazon Bedrock.
Key points
- Loot and UltraVault dashboards were accessible without authentication, exposing collected credentials that could be browsed and searched by victim domain or category.
- Both platforms re-probe credentials; UltraVault reported 42,286 secrets, with 2.7% listed as live.
- UltraVault provides credential validation, AWS key-pair correlation, exploit recommendations, and one-click actions. Researchers could not confirm that all displayed capabilities succeeded against targets.
- Researchers observed compromised AWS credentials used for GetCallerIdentity, model enumeration, and repeated InvokeModel attempts across regions.
- The Bedrock probing later expanded to models from DeepSeek, Mistral, Kimi, and GLM-5; observed user agents included Boto3 on Kali Cloud and Python urllib.
- Datadog said its analysis was limited to unauthenticated domains and that the team did not use or validate exposed credentials.
Article Details
- Attack Vectors
- Both platforms expose plaintext stolen credentials without authentication and support searching by victim domain and credential category. The source does not establish how Loot obtained its credentials.
- UltraVault groups targets into exploitation workflows and offers actions to re-establish code execution on WordPress targets using administrator credentials or an exploitation workflow. Successful execution of these actions was not independently confirmed.
- UltraVault offers backend-dispatched web-shell commands, credential exports, and access persistence through minted credentials.
- A compromised-process reconnaissance workflow requests information about internal ports, metadata endpoints, Kubernetes reachability, and cloud credentials. Researchers could inspect the frontend capability but could not confirm successful access to those resources.
- Researchers observed the dashboard host validating compromised long-term and temporary AWS credentials, enumerating available models, and repeatedly invoking models across regions.
- Defensive Notes
- Monitor credential-validation sequences involving GetCallerIdentity, ListFoundationModels, ListInferenceProfiles, and InvokeModel, especially rapid model invocation across regions.
- Observed user-agent detection opportunities include Boto3 platform strings containing kali-cloud and the bare user agent Python-urllib/3.13. These are behavioral leads, not definitive malicious indicators.
- Monitor temporary AWS credentials as well as long-term access keys; the observed temporary credentials had ASIA-prefixed access key IDs and AssumedRole identities.
- The source lists detection rules for model discovery, cross-region model enumeration and invocation, invocation from a new ASN with a new model ID, impossible travel involving IAM user keys, and generation of temporary security credentials.
- Platform inventory totals and live-credential rates are dashboard-reported figures. Capability evidence varies between frontend implementation, backend action requests, and backend-reported results.
- Researchers withheld indicators to protect victims' exposed credentials and stated that they did not use or validate those credentials.
MITRE ATT&CK
T1046 · Network Service DiscoveryUltraVault's rsc_escalate workflow requests internal open-port reconnaissance from a compromised Node process, but researchers could not confirm that the requested resources were successfully reached.T1068 · Exploitation for Privilege EscalationUltraVault presents a matrix of 14 local privilege escalation vulnerabilities and recommends an exploit for a host where the attacker already has access; successful exploitation was not established.T1078.004 · Cloud AccountsThe dashboard host used compromised long-term AWS access keys and temporary STS credentials to validate identities and access Amazon Bedrock.T1087.004 · Cloud AccountObserved GetCallerIdentity calls checked the identity associated with compromised AWS credentials; UltraVault also displays account IDs and ARNs returned by credential-pair validation.T1496 · Resource HijackingResearchers observed repeated InvokeModel attempts using compromised AWS credentials to determine which hosted models would process requests.T1505.003 · Web ShellUltraVault exposes functionality for dispatching commands to web shells through its backend and attempting to reopen lost shells; execution was not independently confirmed.T1526 · Cloud Service DiscoveryObserved ListFoundationModels and ListInferenceProfiles calls enumerated Amazon Bedrock resources accessible with compromised credentials.
CVE
CVE-2025-55182The interface groups targets under five named exploitation chains: react2shell (CVE-2025-55182), wp2shell (CVE-2026-63030 and CVE-2026-60137), xss2shell (CVE-2026-64638), joomla2shell (CVE-2026-48907), and deep.CVE-2026-48907The interface groups targets under five named exploitation chains: react2shell (CVE-2025-55182), wp2shell (CVE-2026-63030 and CVE-2026-60137), xss2shell (CVE-2026-64638), joomla2shell (CVE-2026-48907), and deep.CVE-2026-60137The interface groups targets under five named exploitation chains: react2shell (CVE-2025-55182), wp2shell (CVE-2026-63030 and CVE-2026-60137), xss2shell (CVE-2026-64638), joomla2shell (CVE-2026-48907), and deep.CVE-2026-63030The interface groups targets under five named exploitation chains: react2shell (CVE-2025-55182), wp2shell (CVE-2026-63030 and CVE-2026-60137), xss2shell (CVE-2026-64638), joomla2shell (CVE-2026-48907), and deep.CVE-2026-64638The interface groups targets under five named exploitation chains: react2shell (CVE-2025-55182), wp2shell (CVE-2026-63030 and CVE-2026-60137), xss2shell (CVE-2026-64638), joomla2shell (CVE-2026-48907), and deep.
Vendors
Anthropic"anthropic":{"count":114,"live":10},"azure_openai_key":{"count":99,"live":0},AWSUltraVault has dedicated endpoints for correlating and validating AWS secrets, indicating a more substantial focus on AWS:DatadogSince July 2026, the Datadog Security Research team has been monitoring a set of credential harvesting platforms that inventory, validate, and take additional actions using compromised credentials.DeepSeek"elevenlabs":{"count":32,"live":11},"deepseek":{"count":20,"live":2},Mistral"mistral":{"count":5,"live":4},"cohere":{"count":1,"live":1},OpenAI"providers":{"openai":{"count":699,"live":93},"gemini":{"count":666,"live":55},
Products
Amazon BedrockFrom the host serving these dashboards, we see the probing behavior in action through live Amazon Bedrock abuse using GetCallerIdentity, ListFoundationModels, and InvokeModel calls.Cloud SIEMCloud SIEM:cPanelIn the image below, the attack targets port 2083, associated with cPanel.WordPressThe UltraVault LPE matrix recommending local privilege escalation vulnerabilities against a WordPress host.
Tools
LootThe first, which we refer to as Loot, is a simple credential catalog with a search box and an interactive validate button.Reconand control (C2) server hosting an automated reconnaissance and credential management framework dubbed “Recon.” GTIG described the host as providing “a live, production frontend dashboard designed to organize,UltraVaultThe second, UltraVault, is a dashboard that provides one-click buttons for validation of credentials, determines the best exploit to deploy against a vulnerability based on the compromised infrastructure, and