logo

New Developments in LLM Hijacking Activity

ID: af611228-f7b8-5709-98ab-017d41a8d502

STIX ID: report--af611228-f7b8-5709-98ab-017d41a8d502

Feed Name: Wiz Blog

Threat Score
65/100

Date Published: 2024-12-15

Date Updated: 2026-05-01

...
...

**Executive Summary:** Wiz Research observed a campaign by JINX-2401 abusing compromised AWS IAM credentials to attempt Bedrock model hijacking across multiple environments; the actor created IAM users matching the regex ^[A-Z][a-z]{5}[0-9]{3}$ and a policy named New_Policy granting bedrock invocation permissions, used Proton VPN IPs and Python/Boto3 user-agents, and attempted model agreement/API calls that were mostly blocked by Service Control Policies (SCPs); the report supplies IOCs, detection queries, and SCP-based mitigation recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.