logo

LLM Hijacking Targeting AWS (Campaign)

ID: a845321c-fda5-5b62-9670-2b98886e5044

STIX ID: report--a845321c-fda5-5b62-9670-2b98886e5044

Feed Name: Wiz Cloud Threat Landscape

Threat Score
70/100

Date Published: 2024-12-15

Date Updated: 2026-05-01

Author: [email protected] (Wiz Threat Research)

...
...

Wiz Threat Research identified JINX-2401 on 2024-11-26 as a threat actor leveraging compromised IAM user keys to access multiple AWS environments and attempt hijacking of Bedrock LLM models. The attacker created privileged IAM users/policies, attempted to complete foundation model agreements via API calls (e.g., PutUseCaseForModelAccess, CreateFoundationModelAgreement) and used Proton VPN IPs, but Service Control Policies prevented successful model invocation; consistent naming patterns indicate a targeted, systematic campaign.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.