Cybersecurity firm Darktrace reports that attackers compromised a LiteLLM-Proxy gateway on Amazon Bedrock via exposed SSH credentials to conduct unauthorized XMRig cryptocurrency mining and illicit cloud activity.
Key Points
- Attackers exploited an Amazon EC2 instance running LiteLLM-Proxy that was incorrectly configured to accept public SSH connections.
- The compromised gateway was used to deploy XMRig software, which initiated unauthorized cryptocurrency mining operations.
- Darktrace identified suspicious IAM activity, including unauthorized attempts to enumerate Amazon Bedrock models and create new user accounts.
- Forensic analysis traced the malicious activity to IP addresses located in Vietnam.
- Security experts recommend enforcing strict port closures, implementing least-privilege IAM roles, and monitoring cloud control planes to prevent similar breaches.