Cloud · 18h ago

Datadog Spots Bedrock Checks in Stolen AWS Keys

Datadog Security Labs found multiple credential-harvesting platforms now doing Amazon Bedrock-specific checks on stolen AWS keys, and one platform, KMON_NOC, has been targeting customers since August 31, 2026 across more than 80 Datadog Cloud SIEM customers. The tools first verify that an AWS key is live, then test whether it can invoke Bedrock models, treating that as a separate sign of value.

In plain terms, the harvesters are sorting credentials by what they can do, not just whether they work. A key that can reach Bedrock is worth more on the resale market because it can be used to consume or resell model access, so simple “is this key valid?” triage misses the privilege attackers are monetizing.

For AWS shops, especially those using Bedrock or other hosted AI services, the exposure follows the credential. If a leaked key can call model APIs, it has a different resale value and a different downstream abuse profile than a key that only opens the account.

Timeline

Sources

1 source covering this story

Part of the PlainSec briefing for 2026-10-06

Editions