New Developments in LLM Hijacking Activity
ID: af611228-f7b8-5709-98ab-017d41a8d502
STIX ID: report--af611228-f7b8-5709-98ab-017d41a8d502
Feed Name: Wiz Blog
**Executive Summary:** Wiz Research observed a campaign by JINX-2401 abusing compromised AWS IAM credentials to attempt Bedrock model hijacking across multiple environments; the actor created IAM users matching the regex ^[A-Z][a-z]{5}[0-9]{3}$ and a policy named New_Policy granting bedrock invocation permissions, used Proton VPN IPs and Python/Boto3 user-agents, and attempted model agreement/API calls that were mostly blocked by Service Control Policies (SCPs); the report supplies IOCs, detection queries, and SCP-based mitigation recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
