Skip to content
MediumNewsLLM-specific

Beyond valid credentials: How exposed AWS keys are tested for Amazon Bedrock access

Published
Record updated
View JSON

Summary

Unit 42 describes validation patterns attackers use to test stolen AWS credentials for Amazon Bedrock access. It observed the KMON_NOC credential harvesting platform, which targets Datadog Cloud SIEM customers, and analyzed its public JavaScript bundle. The frontend first checks keys with STS GetCallerIdentity using SigV4 signing, then separately checks for Bedrock access and tracks keysWithBedrock in its dashboard.