AUTO-UPDATED

'Cryptomining can be a lucrative post-compromise activity in cloud environments': Experts warn AI gateways connected to Amazon Bedrock are being hijacked to steal crypto

Cybersecurity firm Darktrace reports that attackers compromised a LiteLLM-Proxy gateway on Amazon Bedrock via exposed SSH credentials to conduct unauthorized XMRig cryptocurrency mining and illicit cloud activity.

Key Points

  • Attackers exploited an Amazon EC2 instance running LiteLLM-Proxy that was incorrectly configured to accept public SSH connections.
  • The compromised gateway was used to deploy XMRig software, which initiated unauthorized cryptocurrency mining operations.
  • Darktrace identified suspicious IAM activity, including unauthorized attempts to enumerate Amazon Bedrock models and create new user accounts.
  • Forensic analysis traced the malicious activity to IP addresses located in Vietnam.
  • Security experts recommend enforcing strict port closures, implementing least-privilege IAM roles, and monitoring cloud control planes to prevent similar breaches.

Why it Matters

This incident highlights the growing security risks associated with centralized AI gateways that hold privileged access to generative AI models. Organizations must secure these infrastructure components to prevent attackers from leveraging them as entry points for cryptojacking or broader cloud credential theft.
TechRadar Published by Sead Fadilpašić
Read original