Hackers Compromise AWS AI Gateway Connected to Amazon Bedrock to Deploy XMRig Cryptominer
ID: 4b8fe69f-6766-5d8f-a4ae-56ca57a2dcfe
STIX ID: report--4b8fe69f-6766-5d8f-a4ae-56ca57a2dcfe
Feed Name: GBHackers
A Darktrace-detected compromise of an AWS EC2 AI gateway (LiteLLM-Proxy) occurred after exposed SSH was brute-forced, enabling the download of XMRig cryptomining malware from an external IP and subsequent connections to a mining pool; the SOC escalated the detection and later observed anomalous IAM activity (suspicious Bedrock-related API calls and a CreateUser attempt) from an unusual IP, raising concerns about credential misuse and persistence in an environment that centralizes privileged model and cloud access.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
