LLMJacking for Roleplaying Campaign (Campaign)
ID: 4928bbe3-e016-56f2-8574-d13428fbc041
STIX ID: report--4928bbe3-e016-56f2-8574-d13428fbc041
Feed Name: Wiz Cloud Threat Landscape
Date Published: 2024-10-03
Date Updated: 2026-05-01
Author: [email protected] (Wiz Threat Research)
Threat actors leveraged exposed long‑lived AWS credentials found in public repositories to programmatically hijack AWS Bedrock (notably Anthropic Claude) over a three‑phase workflow—checking model availability, requesting console-only access with falsified business reasons, then invoking models with jailbreak prompts. Over ~48 hours researchers observed ~75,000 successful invocations from 12 ASNs, with the compute routed to a roleplay platform (Chub.ai) and generation of policy-violating content including sexual, violent, and CSEM material; AWS subsequently updated its compromised-key quarantine policy to block Bedrock operations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
