Cloud · 18h ago
Datadog Security Labs found multiple credential-harvesting platforms now doing Amazon Bedrock-specific checks on stolen AWS keys, and one platform, KMON_NOC, has been targeting customers since August 31, 2026 across more than 80 Datadog Cloud SIEM customers. The tools first verify that an AWS key is live, then test whether it can invoke Bedrock models, treating that as a separate sign of value.
In plain terms, the harvesters are sorting credentials by what they can do, not just whether they work. A key that can reach Bedrock is worth more on the resale market because it can be used to consume or resell model access, so simple “is this key valid?” triage misses the privilege attackers are monetizing.
For AWS shops, especially those using Bedrock or other hosted AI services, the exposure follows the credential. If a leaked key can call model APIs, it has a different resale value and a different downstream abuse profile than a key that only opens the account.
1 source covering this story
In this post, we share LLM-specific validation patterns that attackers use to test exposed AWS credentials for Amazon Bedrock access.
Part of the PlainSec briefing for 2026-10-06