logo

LLMJacking for Roleplaying Campaign (Campaign)

ID: 4928bbe3-e016-56f2-8574-d13428fbc041

STIX ID: report--4928bbe3-e016-56f2-8574-d13428fbc041

Feed Name: Wiz Cloud Threat Landscape

Threat Score
70/100

Date Published: 2024-10-03

Date Updated: 2026-05-01

Author: [email protected] (Wiz Threat Research)

...
...

Threat actors leveraged exposed long‑lived AWS credentials found in public repositories to programmatically hijack AWS Bedrock (notably Anthropic Claude) over a three‑phase workflow—checking model availability, requesting console-only access with falsified business reasons, then invoking models with jailbreak prompts. Over ~48 hours researchers observed ~75,000 successful invocations from 12 ASNs, with the compute routed to a roleplay platform (Chub.ai) and generation of policy-violating content including sexual, violent, and CSEM material; AWS subsequently updated its compromised-key quarantine policy to block Bedrock operations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.