Datadog Tracks AI-Assisted Credential-Harvesting Platforms and AWS Abuse

· Original article ↗

Summary

Datadog researchers analyzed two exposed credential-harvesting dashboards that validate stolen secrets and support post-exploitation actions, and observed attempts to use compromised AWS credentials to probe and access Amazon Bedrock.

Key points

  • Loot and UltraVault dashboards were accessible without authentication, exposing collected credentials that could be browsed and searched by victim domain or category.
  • Both platforms re-probe credentials; UltraVault reported 42,286 secrets, with 2.7% listed as live.
  • UltraVault provides credential validation, AWS key-pair correlation, exploit recommendations, and one-click actions. Researchers could not confirm that all displayed capabilities succeeded against targets.
  • Researchers observed compromised AWS credentials used for GetCallerIdentity, model enumeration, and repeated InvokeModel attempts across regions.
  • The Bedrock probing later expanded to models from DeepSeek, Mistral, Kimi, and GLM-5; observed user agents included Boto3 on Kali Cloud and Python urllib.
  • Datadog said its analysis was limited to unauthenticated domains and that the team did not use or validate exposed credentials.

Article Details

Attack Vectors
  • Both platforms expose plaintext stolen credentials without authentication and support searching by victim domain and credential category. The source does not establish how Loot obtained its credentials.
  • UltraVault groups targets into exploitation workflows and offers actions to re-establish code execution on WordPress targets using administrator credentials or an exploitation workflow. Successful execution of these actions was not independently confirmed.
  • UltraVault offers backend-dispatched web-shell commands, credential exports, and access persistence through minted credentials.
  • A compromised-process reconnaissance workflow requests information about internal ports, metadata endpoints, Kubernetes reachability, and cloud credentials. Researchers could inspect the frontend capability but could not confirm successful access to those resources.
  • Researchers observed the dashboard host validating compromised long-term and temporary AWS credentials, enumerating available models, and repeatedly invoking models across regions.
Defensive Notes
  • Monitor credential-validation sequences involving GetCallerIdentity, ListFoundationModels, ListInferenceProfiles, and InvokeModel, especially rapid model invocation across regions.
  • Observed user-agent detection opportunities include Boto3 platform strings containing kali-cloud and the bare user agent Python-urllib/3.13. These are behavioral leads, not definitive malicious indicators.
  • Monitor temporary AWS credentials as well as long-term access keys; the observed temporary credentials had ASIA-prefixed access key IDs and AssumedRole identities.
  • The source lists detection rules for model discovery, cross-region model enumeration and invocation, invocation from a new ASN with a new model ID, impossible travel involving IAM user keys, and generation of temporary security credentials.
  • Platform inventory totals and live-credential rates are dashboard-reported figures. Capability evidence varies between frontend implementation, backend action requests, and backend-reported results.
  • Researchers withheld indicators to protect victims' exposed credentials and stated that they did not use or validate those credentials.

MITRE ATT&CK

CVE

Vendors

Products

Tools

Related Articles