Intelligence Briefing — Security Arsenal | From The Dark Side Classification: TLP:WHITE | Pulse Source: AlienVault OTX | Last Observed: 2026-10-07
Threat Summary
Open Threat Exchange telemetry has surfaced an emerging and financially motivated threat pattern: adversaries are no longer treating stolen AWS access keys as generic cloud credentials. Instead, they are validating keys specifically for Amazon Bedrock access — probing whether a compromised identity can invoke large language model endpoints such as Anthropic Claude.
The attack chain observed across this pulse follows a consistent three-stage validation workflow:
- Credential Acquisition — AWS access keys are harvested from exposed Git repositories, leaked
.envfiles, compromised CI/CD pipelines, infostealer logs traded on dark web marketplaces, and misconfigured S3 buckets. - Identity Validation — The key is tested via
sts:GetCallerIdentityto confirm it is live and to enumerate the associated account and ARN. - Capability Probing — Validated keys are tested against Bedrock using
bedrock:ListFoundationModelsand subsequentInvokeModelcalls to determine whether the victim account has LLM access enabled.
Keys that pass all three stages are either monetized directly (sold as "Bedrock-capable AWS accounts" on criminal marketplaces) or abused in place — a technique increasingly referred to as LLMjacking, where attackers consume the victim's LLM quota for their own AI workloads, spam generation, phishing content creation, or resale of proxied model access. The financial impact lands entirely on the victim's AWS bill, and the reputational/abuse risk lands on the victim's account.
The pulse identifies KMON_NOC as one of multiple purpose-built credential harvesting and validation platforms operationalizing this workflow at scale, with distributed probing infrastructure spanning consumer and hosted IP space across Southeast Asia, Eastern Europe, and Western Europe.
Threat Actor / Malware Profile
Attribution: Unknown — financially motivated, likely access-broker ecosystem Named Platform: KMON_NOC (credential harvesting & validation platform)
Platform Behavior
KMON_NOC is not a traditional malware family — it is an automated credential validation pipeline operated as attacker infrastructure. Its observed behavior profile:
- Distribution / Input: Ingests bulk AWS key material from stealer logs, paste sites, GitHub/GitLab secret-scanning leaks, and marketplace dumps. Keys are queued for automated validation.
- Validation Sequence:
GetCallerIdentity(STS) — confirms the key is active; this call cannot be denied and generates a CloudTrail event in the victim account regardless of IAM policy.ListFoundationModels(Bedrock) — determines whether Bedrock is enabled in the account and which model providers (Anthropic, Meta, Mistral, etc.) are accessible.InvokeModel/Converse— active probing to confirm usable inference quota, often using minimal-token test prompts to avoid billing noise.
- C2 / Probing Communication: Validation traffic originates from the distributed IPv4 infrastructure listed in the IOC section. User-Agent strings typically masquerade as legitimate
aws-cliorBoto3SDK traffic, blending with normal developer tooling. - Persistence Mechanism: On the attacker side, validated keys are cataloged in backend databases keyed by account ID, region, enabled model list, and quota. On the victim side, no malware is installed — persistence is the stolen key itself, which remains valid until rotated or deactivated.
- Anti-Analysis / Evasion:
- Probing is low-and-slow: single API calls per key per source IP to avoid rate-based alerting.
- Use of residential and mixed ASN space to defeat geo-fencing heuristics.
- Minimal-token
InvokeModelcalls sized to stay under billing anomaly thresholds. - Rotation across the observed IP pool (e.g.,
103.160.185.100,112.78.151.90,78.109.78.211) to avoid per-IP reputation blocking.
Strategic Implication
This represents a maturation of the access-broker economy: credentials are now graded by AI capability before sale. An AWS key with Bedrock access commands a premium because it can be immediately monetized through LLMjacking without any further intrusion work.
IOC Analysis
The pulse contains 36 indicators, dominated by two types:
IPv4 Addresses (Probing / Validation Infrastructure)
| Indicator | Type | Role |
|---|---|---|
| 112.78.151.90 | IPv4 | Credential validation origin |
| 78.109.78.211 | IPv4 | Credential validation origin |
| 83.194.172.248 | IPv4 | Credential validation origin |
| 103.160.185.100 | IPv4 | Credential validation origin |
| 109.146.93.39 | IPv4 | Credential validation origin |
| 115.138.247.83 | IPv4 | Credential validation origin |
These are the source IPs from which GetCallerIdentity and ListFoundationModels calls originate. SOC teams should hunt these in AWS CloudTrail (sourceIPAddress), VPC Flow Logs, WAF logs, and any outbound proxy telemetry if internal tooling communicates with this infrastructure.
File Hashes (SHA256)
| Indicator | Role |
|---|---|
| 923641364ef0ce3a6f1d944890244082b8c7f29c9600c0433b2a0ca9822c0608 | Associated tooling / sample artifact |
| c9335bb8a21bd2c568d03b040fb86a0e72145691e54a33495ee0cfaac55835dc | Associated tooling / sample artifact |
These hashes should be swept across EDR platforms, email gateways, and any host where credential-harvesting tooling may have been staged. Hashes decay quickly — prioritize them for retro-hunts rather than forward blocking.
Operationalization Guidance
- Ingest all 36 indicators into your TIP/SIEM with a 30-day retroactive lookback window — key validation often precedes abuse by days or weeks.
- Prioritize CloudTrail as the primary detection plane. Network IOCs are only useful if you can correlate them to AWS API events; the API call pattern itself is the stronger signal.
- Tooling: CloudTrail Lake / Athena queries, Sigma (below), Microsoft Sentinel (KQL below), and AWS GuardDuty (which natively detects
UnauthorizedAccess:IAMUser/InstanceCredentialExfiltrationand anomalous Bedrock usage) should be layered together.
Detection Engineering
Sigma Rules
---
title: Suspicious AWS Credential Validation - GetCallerIdentity from External IP
id: 7f3a2c1e-9b4d-4e5a-a1c2-8d6f0e1b2c3d
status: experimental
description: Detects STS GetCallerIdentity calls originating from known credential-validation infrastructure or non-corporate IP space, consistent with KMON_NOC-style stolen key validation observed in OTX pulse data.
author: Security Arsenal Threat Intelligence
date: 2026/10/09
references:
- https://securitylabs.datadoghq.com/articles/beyond-valid-credentials-how-exposed-aws-keys-are-tested-for-amazon-bedrock-access
logsource:
product: aws
service: cloudtrail
detection:
selection_event:
eventSource: sts.amazonaws.com
eventName: GetCallerIdentity
selection_badip:
sourceIPAddress:
- 112.78.151.90
- 78.109.78.211
- 83.194.172.248
- 103.160.185.100
- 109.146.93.39
- 115.138.247.83
condition: selection_event and selection_badip
falsepositives:
- Legitimate developer tooling from VPN egress if IPs overlap (unlikely for listed infrastructure)
level: high
tags:
- attack.discovery
- attack.t1087
- attack.t1078
---
title: Amazon Bedrock Foundation Model Enumeration - Potential LLMjacking Recon
id: 2b8c4d5f-1a3e-4f6b-b2d3-9c7e1f0a3d4e
status: experimental
description: Detects Bedrock ListFoundationModels or GetFoundationModel calls from IAM identities that have no prior Bedrock usage baseline, indicating capability probing of stolen AWS keys for LLM access.
author: Security Arsenal Threat Intelligence
date: 2026/10/09
references:
- https://securitylabs.datadoghq.com/articles/beyond-valid-credentials-how-exposed-aws-keys-are-tested-for-amazon-bedrock-access
logsource:
product: aws
service: cloudtrail
detection:
selection:
eventSource: bedrock.amazonaws.com
eventName:
- ListFoundationModels
- GetFoundationModel
- ListModelCustomizationJobs
filter_known_bedrock_users:
userIdentity.type:
- AssumedRole
userIdentity.principalId|contains:
- bedrock-automation
- approved-ml-pipeline
condition: selection and not filter_known_bedrock_users
falsepositives:
- Developers exploring Bedrock for the first time in sandbox accounts
- New ML pipeline onboarding
level: medium
tags:
- attack.discovery
- attack.t1526
- attack.t1078
---
title: Bedrock InvokeModel from Identity Without Prior Bedrock History - Token Jacking
id: 9e1d6a7b-3c5f-4a8b-c4e5-0d2f1a3b4c5d
status: experimental
description: Detects Bedrock InvokeModel/Converse API calls immediately following GetCallerIdentity from the same identity within a short window — the signature KMON_NOC validation-to-abuse sequence.
author: Security Arsenal Threat Intelligence
date: 2026/10/09
references:
- https://securitylabs.datadoghq.com/articles/beyond-valid-credentials-how-exposed-aws-keys-are-tested-for-amazon-bedrock-access
logsource:
product: aws
service: cloudtrail
detection:
selection:
eventSource: bedrock.amazonaws.com
eventName:
- InvokeModel
- InvokeModelWithResponseStream
- Converse
- ConverseStream
condition: selection
timeframe: 15m
correlation:
type: temporal
rules:
- Suspicious AWS Credential Validation - GetCallerIdentity from External IP
group-by:
- userIdentity.accessKeyId
falsepositives:
- CI/CD jobs that validate identity then invoke models (baseline these principals)
level: critical
tags:
- attack.impact
- attack.t1496
- attack.t1078
Microsoft Sentinel (KQL)
This hunt assumes AWS CloudTrail is ingested into the AWSCloudTrail table (via the Sentinel AWS connector) and correlates endpoint-side key exposure attempts with cloud-side validation behavior.
// Hunt: Stolen AWS key validation for Bedrock access (KMON_NOC pattern)
// Part 1: CloudTrail validation + probing sequence from known bad IPs or unusual sources
let BadIPs = dynamic(["112.78.151.90","78.109.78.211","83.194.172.248","103.160.185.100","109.146.93.39","115.138.247.83"]);
let Validation =
AWSCloudTrail
| where TimeGenerated > ago(30d)
| where EventSource == "sts.amazonaws.com" and EventName == "GetCallerIdentity"
| project KeyId = UserIdentityAccessKeyId, Identity = UserIdentityPrincipalId, ValidationTime = TimeGenerated, SourceIP = SourceIpAddress, Account = RecipientAccountId;
let BedrockProbe =
AWSCloudTrail
| where TimeGenerated > ago(30d)
| where EventSource == "bedrock.amazonaws.com"
| where EventName in ("ListFoundationModels","GetFoundationModel","InvokeModel","InvokeModelWithResponseStream","Converse","ConverseStream")
| project KeyId = UserIdentityAccessKeyId, ProbeTime = TimeGenerated, ProbeEvent = EventName, ProbeIP = SourceIpAddress, Region = AwsRegion;
Validation
| join kind=inner BedrockProbe on KeyId
| where ProbeTime between (ValidationTime .. ValidationTime + 1h)
| extend KnownBadIP = SourceIP in (BadIPs) or ProbeIP in (BadIPs)
| summarize FirstValidation = min(ValidationTime), ProbeEvents = make_set(ProbeEvent), Regions = make_set(Region), SourceIPs = make_set(SourceIP), ProbeIPs = make_set(ProbeIP), MaxKnownBad = max(KnownBadIP) by KeyId, Identity, Account
| order by MaxKnownBad desc, FirstValidation desc;
// Part 2: Endpoint hunt — processes accessing AWS credential files followed by cloud SDK network activity
DeviceProcessEvents
| where TimeGenerated > ago(14d)
| where ProcessCommandLine has_any (".aws\\credentials", ".aws/credentials", "aws_access_key_id", "aws_secret_access_key")
| where InitiatingProcessFileName !in~ ("aws.exe", "python.exe", "code.exe", "terraform.exe")
| project DeviceName, FileName, ProcessCommandLine, InitiatingProcessFileName, TimeGenerated
| join kind=leftouter (
DeviceNetworkEvents
| where TimeGenerated > ago(14d)
| where RemoteUrl has_any ("bedrock", "sts.amazonaws.com") or RemoteIP in ("112.78.151.90","78.109.78.211","83.194.172.248","103.160.185.100","109.146.93.39","115.138.247.83")
| project DeviceName, RemoteUrl, RemoteIP, NetTime = TimeGenerated
) on DeviceName
| order by TimeGenerated desc;
PowerShell IOC Hunt Script
Run on endpoints and build servers to hunt for exposed AWS credential material, suspicious AWS CLI/SDK invocation artifacts, and connections to known validation infrastructure.
# Security Arsenal - KMON_NOC / AWS Bedrock Token-Jacking Hunt
# Searches for exposed AWS keys, suspicious AWS CLI usage, and bad-IP connections
# Run elevated. Outputs to C:\HuntResults\aws_tokenjack_hunt_<timestamp>.txt
$ErrorActionPreference = 'SilentlyContinue'
$BadIPs = @("112.78.151.90","78.109.78.211","83.194.172.248","103.160.185.100","109.146.93.39","115.138.247.83")
$BadHashes = @(
"923641364ef0ce3a6f1d944890244082b8c7f29c9600c0433b2a0ca9822c0608",
"c9335bb8a21bd2c568d03b040fb86a0e72145691e54a33495ee0cfaac55835dc"
)
$OutDir = "C:\HuntResults"
New-Item -ItemType Directory -Path $OutDir -Force | Out-Null
$Out = Join-Path $OutDir ("aws_tokenjack_hunt_" + (Get-Date -Format 'yyyyMMdd_HHmmss') + ".txt")
function Log($msg) { $line = "[{0}] {1}" -f (Get-Date -Format 'u'), $msg; Write-Host $line; Add-Content -Path $Out -Value $line }
Log "=== AWS Token-Jacking Hunt Started ==="
# 1. Active / recent connections to validation infrastructure
Log "--- [1] Checking network connections to known validation IPs ---"
$conns = Get-NetTCPConnection | Where-Object { $BadIPs -contains $_.RemoteAddress }
if ($conns) {
foreach ($c in $conns) {
$proc = Get-Process -Id $c.OwningProcess
Log ("ALERT: Connection to {0}:{1} from PID {2} ({3}) State={4}" -f $c.RemoteAddress, $c.RemotePort, $c.OwningProcess, $proc.ProcessName, $c.State)
}
} else { Log "OK: No active connections to known validation IPs." }
# 2. Exposed AWS credential files on disk
Log "--- [2] Locating AWS credential files and checking permissions ---"
$credPaths = @("$env:USERPROFILE\.aws\credentials", "C:\Users\*\.aws\credentials", "$env:ProgramData\Amazon\AWSCLI")
foreach ($p in $credPaths) {
Get-Item $p | ForEach-Object {
Log ("FOUND credential file: {0} (LastWrite: {1})" -f $_.FullName, $_.LastWriteTime)
$content = Get-Content $_.FullName -Raw
if ($content -match "aws_secret_access_key\s*=\s*\S+") { Log "WARNING: Live secret key material present in $($_.FullName) - rotate if unneeded." }
}
}
# 3. Scan common dev locations for hardcoded AWS keys (AKIA pattern)
Log "--- [3] Scanning repos/scripts for hardcoded AKIA-style access keys ---"
$searchRoots = @("$env:USERPROFILE\source", "$env:USERPROFILE\repos", "$env:USERPROFILE\Documents")
foreach ($root in $searchRoots) {
if (Test-Path $root) {
Get-ChildItem $root -Recurse -Include *.env,*.cfg,*.ini,*.json,*.yaml,*.yml,*.ps1,*.py -ErrorAction SilentlyContinue |
Select-String -Pattern "AKIA[0-9A-Z]{16}" -List |
ForEach-Object { Log ("ALERT: Hardcoded AWS key pattern in {0} line {1}" -f $_.Path, $_.LineNumber) }
}
}
# 4. Suspicious AWS CLI / SDK process artifacts in Prefetch & recent PowerShell history
Log "--- [4] Reviewing PowerShell history for credential-access or Bedrock commands ---"
$psHistory = "$env:APPDATA\Microsoft\Windows\PowerShell\PSReadLine\ConsoleHost_history.txt"
if (Test-Path $psHistory) {
Select-String -Path $psHistory -Pattern "Get-CallerIdentity|GetCallerIdentity|ListFoundationModels|InvokeModel|bedrock|aws sts" |
ForEach-Object { Log ("ALERT: Suspicious PS history entry: {0}" -f $_.Line.Trim()) }
}
# 5. Hash sweep for associated tooling in common staging dirs
Log "--- [5] Hash-sweeping staging directories for known tool artifacts ---"
$staging = @("$env:TEMP", "C:\Users\Public", "$env:ProgramData")
foreach ($dir in $staging) {
Get-ChildItem $dir -Recurse -File -ErrorAction SilentlyContinue | ForEach-Object {
$h = (Get-FileHash $_.FullName -Algorithm SHA256 -ErrorAction SilentlyContinue).Hash
if ($BadHashes -contains $h) { Log ("CRITICAL: Known malicious artifact hash match: {0} ({1})" -f $_.FullName, $h) }
}
}
# 6. Check for scheduled tasks invoking aws.exe from unusual contexts
Log "--- [6] Auditing scheduled tasks referencing AWS tooling ---"
Get-ScheduledTask | ForEach-Object {
$actions = $_.Actions | Out-String
if ($actions -match "aws\.exe|bedrock|GetCallerIdentity") {
Log ("REVIEW: Task '{0}' invokes AWS tooling -> {1}" -f $_.TaskName, ($actions -replace "\s+"," "))
}
}
Log "=== Hunt Complete. Results: $Out ==="
Response Priorities
Immediate (0–4 hours)
- Block the six validation IPs at egress firewalls, WAF, and cloud network ACLs; import all 36 IOCs into the SIEM/TIP with a 30-day retroactive sweep.
- Query CloudTrail (all regions, all accounts) for
GetCallerIdentity,ListFoundationModels, andInvokeModelevents sourced from the listed IPs or from identities with no historical Bedrock usage. - Run the PowerShell hunt on build servers, developer workstations, and any host with AWS CLI installed; flag hardcoded
AKIAkeys.
24 Hours
- Rotate every AWS access key found in endpoint scans, code repositories, or CI/CD logs — treat any externally validated key as fully compromised.
- Verify identity posture: enforce MFA on all IAM users, audit for dormant IAM users with active access keys, and disable keys unused for 90+ days.
- Review AWS billing and Bedrock usage dashboards for anomalous inference spend — LLMjacking often surfaces first as a cost anomaly.
- Confirm GuardDuty is enabled in all regions, including regions where you run no workloads (attackers probe unused regions).
1 Week
- Eliminate long-lived access keys in favor of IAM Roles, SSO/federated identity (IAM Identity Center), and instance profiles. Long-lived keys are the entire attack surface here.
- Apply SCPs (Service Control Policies) to deny Bedrock access organization-wide except in explicitly approved accounts/regions; add
aws:RequestedRegionconditions. - Enable CloudTrail data events and Bedrock model invocation logging to S3 with alerting on first-time
InvokeModelper identity. - Deploy secret-scanning (pre-commit hooks + CI pipeline scanning) to stop keys from reaching repositories in the first place.
- Tune the Sigma correlation rule (rule 3) against a 30-day baseline of legitimate Bedrock principals to reduce noise before enabling critical-tier paging.
This briefing is derived from live AlienVault OTX pulse telemetry and reflects threat activity observed as of 2026-10-09. Indicators have a limited shelf life — the behavioral detections above are the durable control.
Related Resources
Security Arsenal Incident Response Managed SOC & MDR Services AlertMonitor Threat Detection From The Dark Side Intel Hub
Is your security operations ready?
Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.