Beyond valid credentials: How exposed AWS keys are tested for Amazon Bedrock access
Description
Attackers who obtain AWS credentials are actively validating them to determine their usefulness for accessing Amazon Bedrock services. Credential harvesting platforms, including KMON_NOC, test stolen AWS keys by calling GetCallerIdentity, then verifying Bedrock access through ListFoundationModels and Converse API calls. This validation enables attackers to assess the value of credentials for resale in token-jacking markets, where stolen AI model access is sold below retail price. The testing targets Anthropic Claude models and enumerates promotional credits to estimate financial worth. This behavior represents an evolution in credential validation techniques similar to those previously observed with AWS SES and SNS services.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This campaign involves attackers validating stolen AWS credentials specifically for Amazon Bedrock access. The process begins with verifying the credentials using the AWS GetCallerIdentity API call. If valid, the attackers proceed to test access to Bedrock's large language model capabilities via ListFoundationModels and Converse API calls. The validation scripts, identified on VirusTotal, systematically test credentials across multiple AWS regions, focusing on Anthropic Claude models and enumerating promotional credits to gauge the financial value of the compromised accounts. This enables attackers to categorize stolen credentials for resale in token-jacking markets, where access to AI models is commoditized. The campaign reflects an evolution in credential validation tactics, paralleling historical patterns seen with AWS SES and SNS services.
Potential Impact
The impact is primarily financial and operational. Validated stolen AWS credentials with Amazon Bedrock access can be resold in underground markets at discounted prices, enabling unauthorized use of AI models and consumption of promotional credits. This can lead to unexpected costs for victims and unauthorized access to AI services. There is no indication of direct exploitation beyond credential validation and resale. No known active exploits or direct attacks leveraging this validation process have been reported.
Defensive Guidance
No official patch or fix is applicable as this is a campaign exploiting stolen credentials. Organizations should focus on securing AWS credentials by enforcing strong credential management practices, including rotating keys regularly, using least privilege principles, enabling multi-factor authentication, and monitoring for unauthorized API calls such as GetCallerIdentity and Bedrock-related API usage. Since this campaign targets stolen credentials, preventing credential compromise is the primary defense. There is no vendor advisory indicating a fix or mitigation at the service level.
Technical Details
- Author
- AlienVault
- Tlp
- white
- References
- ["https://securitylabs.datadoghq.com/articles/beyond-valid-credentials-how-exposed-aws-keys-are-tested-for-amazon-bedrock-access"]
- Pulse Id
- 6ac52c8896a61ee777d4aee5
Indicators of Compromise
Ip
| Value | Description | Copy |
|---|---|---|
ip112.78.151.90 | — | |
ip78.109.78.211 | — | |
ip83.194.172.248 | — | |
ip103.160.185.100 | — | |
ip109.146.93.39 | — | |
ip115.138.247.83 | — | |
ip116.106.179.94 | — | |
ip137.103.56.107 | — | |
ip138.94.168.132 | — | |
ip154.119.213.63 | — | |
ip173.92.116.211 | — | |
ip186.154.182.44 | — | |
ip191.93.177.69 | — | |
ip194.36.27.53 | — | |
ip196.177.214.142 | — | |
ip200.151.53.165 | — | |
ip206.206.119.201 | — | |
ip46.100.30.188 | — | |
ip47.230.250.253 | — | |
ip50.82.6.249 | — | |
ip59.92.240.165 | — | |
ip69.250.15.174 | — | |
ip71.76.4.45 | — | |
ip72.235.197.91 | — | |
ip79.117.129.254 | — | |
ip82.86.130.180 | — | |
ip84.50.134.231 | — | |
ip85.137.52.59 | — | |
ip85.137.53.173 | — | |
ip85.253.221.206 | — | |
ip88.167.240.60 | — | |
ip92.216.157.153 | — | |
ip93.118.107.1 | — | |
ip98.44.224.55 | — |
Hash
| Value | Description | Copy |
|---|---|---|
hash923641364ef0ce3a6f1d944890244082b8c7f29c9600c0433b2a0ca9822c0608 | — | |
hashc9335bb8a21bd2c568d03b040fb86a0e72145691e54a33495ee0cfaac55835dc | — |
Threat ID: 6ac6156e2cdf04f656344b1c
Added to database: 10/07/2026, 09:48:30 UTC
Last enriched: 10/07/2026, 10:03:18 UTC
Last updated: 10/07/2026, 18:48:08 UTC
Views: 21
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.