Attackers are increasingly validating stolen AWS credentials for Amazon Bedrock access, using STS, ListFoundationModels, and Converse to separate ordinary credentials from those that can invoke AI models. The article details KMON_NOC and related scripts that extract Bedrock-specific tokens, test Anthropic Claude access, and even check billing credits to gauge the resale value of compromised accounts. #AmazonBedrock #KMON_NOC #Anthropic #AWS_BEARER_TOKEN_BEDROCK #GetCallerIdentity #ListFoundationModels #Converse
Keypoints
- KMON_NOC is a credential-harvesting platform observed targeting customers since August 31, 2026, with scanning activity seen across more than 80 Datadog Cloud SIEM customers.
- The platform validates AWS access keys with STS GetCallerIdentity and then separately checks whether the credentials can access Amazon Bedrock.
- Its frontend explicitly tracks Bedrock-capable credentials, including fields such as keysWithBedrock and visible “BEDROCK ACCESS” statistics.
- KMON_NOC also extracts and displays AWS_BEARER_TOKEN_BEDROCK, showing interest in harvesting Bedrock-specific bearer tokens directly.
- Other exposed scripts used ListFoundationModels, ListInferenceProfiles, and Converse to probe Bedrock reachability and model invocation across multiple regions.
- One script also queried billing:GetCredits to estimate remaining promotional credit and the financial value of compromised accounts.
- Defenders are advised to monitor unusual Bedrock activity, especially from new sources or identities with no prior AI usage, as it may indicate credential validation and possible LLMjacking.
MITRE Techniques
- [T1110 ] Brute Force – Attackers validate stolen credentials by testing whether keys are active and whether they can access Bedrock resources, as described in “validating stolen AWS credentials” and “testing not only whether they are active but also whether they can discover and invoke Amazon Bedrock models.”
- [T1552 ] Unsecured Credentials – The activity focuses on harvesting and using exposed credentials and bearer tokens, including “AWS_BEARER_TOKEN_BEDROCK” and “credentials with Bedrock access.”
- [T1078 ] Valid Accounts – Stolen AWS credentials are checked for real access, with the post noting that “valid credentials then undergo a separate check for Bedrock access” and that successful responses prove usable access.
- [T1528 ] Steal Application Access Token – The platform extracts and copies “AWS_BEARER_TOKEN_BEDROCK,” described as “the environment variable used for Amazon Bedrock API keys.”
- [T1580 ] Cloud Infrastructure Discovery – The scripts enumerate cloud capabilities by calling “ListFoundationModels” and “ListInferenceProfiles” to discover reachable Bedrock models and metadata.
- [T1021 ] Remote Services – Attackers interact remotely with AWS control and runtime APIs such as STS, Bedrock, and Billing to validate and use compromised access.
Indicators of Compromise
- [SHA-256 ] Credential-harvesting scripts analyzed on VirusTotal – c9335bb8a21bd2c568d03b040fb86a0e72145691e54a33495ee0cfaac55835dc, 923641364ef0ce3a6f1d944890244082b8c7f29c9600c0433b2a0ca9822c0608
- [IPv4 ] IP addresses observed performing validation activity since August 31, 2026 – 115.138.247[.]83, 116.106.179[.]94, and other 46 items