AI Gateways Become the Real Cloud Chokepoint

The problem is the gateway, not the miner. If an attacker gets into the proxy that sits between users, Bedrock, and AWS, they may inherit model access, IAM context, and cloud permissions without touching the model provider at all. A cleanup that focuses on the EC2 host misses that the trusted access path itself may be compromised. Darktrace found an AWS EC2 instance running LiteLLM for Amazon Bedrock that was repurposed for XMRig mining. The reporting also says the host was associated with an IAM role that could reach Bedrock resources, and researchers saw attempts to abuse cloud identities and AI services. That makes the proxy a privileged aggregation point, not just another server. The pattern matters beyond this one host. As more teams centralize AI access through gateways, a breach there can become a way to probe models, misuse credentials, and move deeper into the cloud environment even after the original miner is removed.

Part of the PlainSec briefing for 2026-07-10

Sources