LLM Hijacking Targeting AWS (Campaign)
ID: a845321c-fda5-5b62-9670-2b98886e5044
STIX ID: report--a845321c-fda5-5b62-9670-2b98886e5044
Feed Name: Wiz Cloud Threat Landscape
Date Published: 2024-12-15
Date Updated: 2026-05-01
Author: [email protected] (Wiz Threat Research)
Wiz Threat Research identified JINX-2401 on 2024-11-26 as a threat actor leveraging compromised IAM user keys to access multiple AWS environments and attempt hijacking of Bedrock LLM models. The attacker created privileged IAM users/policies, attempted to complete foundation model agreements via API calls (e.g., PutUseCaseForModelAccess, CreateFoundationModelAgreement) and used Proton VPN IPs, but Service Control Policies prevented successful model invocation; consistent naming patterns indicate a targeted, systematic campaign.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
