Skip to main content

Beyond valid credentials: How exposed AWS keys are tested for Amazon Bedrock access

0
Medium
Published: 10/06/2026 (10/06/2026, 17:14:48 UTC)
Source: AlienVault OTX General

Description

Attackers who obtain AWS credentials are actively validating them to determine their usefulness for accessing Amazon Bedrock services. Credential harvesting platforms, including KMON_NOC, test stolen AWS keys by calling GetCallerIdentity, then verifying Bedrock access through ListFoundationModels and Converse API calls. This validation enables attackers to assess the value of credentials for resale in token-jacking markets, where stolen AI model access is sold below retail price. The testing targets Anthropic Claude models and enumerates promotional credits to estimate financial worth. This behavior represents an evolution in credential validation techniques similar to those previously observed with AWS SES and SNS services.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 10/07/2026, 10:03:18 UTC

Technical Analysis

This campaign involves attackers validating stolen AWS credentials specifically for Amazon Bedrock access. The process begins with verifying the credentials using the AWS GetCallerIdentity API call. If valid, the attackers proceed to test access to Bedrock's large language model capabilities via ListFoundationModels and Converse API calls. The validation scripts, identified on VirusTotal, systematically test credentials across multiple AWS regions, focusing on Anthropic Claude models and enumerating promotional credits to gauge the financial value of the compromised accounts. This enables attackers to categorize stolen credentials for resale in token-jacking markets, where access to AI models is commoditized. The campaign reflects an evolution in credential validation tactics, paralleling historical patterns seen with AWS SES and SNS services.

Potential Impact

The impact is primarily financial and operational. Validated stolen AWS credentials with Amazon Bedrock access can be resold in underground markets at discounted prices, enabling unauthorized use of AI models and consumption of promotional credits. This can lead to unexpected costs for victims and unauthorized access to AI services. There is no indication of direct exploitation beyond credential validation and resale. No known active exploits or direct attacks leveraging this validation process have been reported.

Defensive Guidance

No official patch or fix is applicable as this is a campaign exploiting stolen credentials. Organizations should focus on securing AWS credentials by enforcing strong credential management practices, including rotating keys regularly, using least privilege principles, enabling multi-factor authentication, and monitoring for unauthorized API calls such as GetCallerIdentity and Bedrock-related API usage. Since this campaign targets stolen credentials, preventing credential compromise is the primary defense. There is no vendor advisory indicating a fix or mitigation at the service level.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Author
AlienVault
Tlp
white
References
["https://securitylabs.datadoghq.com/articles/beyond-valid-credentials-how-exposed-aws-keys-are-tested-for-amazon-bedrock-access"]
Pulse Id
6ac52c8896a61ee777d4aee5

Indicators of Compromise

Ip

ValueDescriptionCopy
ip112.78.151.90
—
ip78.109.78.211
—
ip83.194.172.248
—
ip103.160.185.100
—
ip109.146.93.39
—
ip115.138.247.83
—
ip116.106.179.94
—
ip137.103.56.107
—
ip138.94.168.132
—
ip154.119.213.63
—
ip173.92.116.211
—
ip186.154.182.44
—
ip191.93.177.69
—
ip194.36.27.53
—
ip196.177.214.142
—
ip200.151.53.165
—
ip206.206.119.201
—
ip46.100.30.188
—
ip47.230.250.253
—
ip50.82.6.249
—
ip59.92.240.165
—
ip69.250.15.174
—
ip71.76.4.45
—
ip72.235.197.91
—
ip79.117.129.254
—
ip82.86.130.180
—
ip84.50.134.231
—
ip85.137.52.59
—
ip85.137.53.173
—
ip85.253.221.206
—
ip88.167.240.60
—
ip92.216.157.153
—
ip93.118.107.1
—
ip98.44.224.55
—

Hash

ValueDescriptionCopy
hash923641364ef0ce3a6f1d944890244082b8c7f29c9600c0433b2a0ca9822c0608
—
hashc9335bb8a21bd2c568d03b040fb86a0e72145691e54a33495ee0cfaac55835dc
—

Threat ID: 6ac6156e2cdf04f656344b1c

Added to database: 10/07/2026, 09:48:30 UTC

Last enriched: 10/07/2026, 10:03:18 UTC

Last updated: 10/07/2026, 18:48:08 UTC

Views: 21

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses