{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/llmjacking/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Bedrock"],"_cs_severities":["low"],"_cs_tags":["cloud","aws","bedrock","llmjacking","persistence"],"_cs_type":"advisory","_cs_vendors":["Amazon"],"content_html":"\u003cp\u003eThis threat brief focuses on detecting unauthorized attempts to enable account-level access to Amazon Bedrock foundation models. Attackers who compromise AWS identities may attempt to enable model entitlements or agree to model EULAs to unlock expensive foundation models for malicious usage, a technique often referred to as LLMjacking. By monitoring for denied control-plane API calls, defenders can identify compromised or under-privileged principals performing boundary-testing. This activity is critical to intercept, as successfully enabling these entitlements provides the necessary persistence for subsequent model invocation and abuse. While access-denied errors can stem from benign permission gaps in CI/CD pipelines or new employee onboarding, recurring unauthorized requests from unexpected source IPs or user agents are strong indicators of potential malicious reconnaissance.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of these Bedrock control-plane functions allows attackers to gain unauthorized access to LLM services, resulting in unauthorized costs, data exfiltration through model interaction, and potential abuse of generative AI capabilities. Organizations that do not monitor for these denied attempts risk missing the initial reconnaissance phase of an LLMjacking attack.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize the investigation of unauthorized Bedrock control-plane activity to identify compromised credentials before they are successfully used to unlock models.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eDeploy the detection rule provided below to your SIEM to monitor for 'AccessDenied' events on Bedrock configuration APIs.\u003c/li\u003e\n\u003cli\u003eEstablish a baseline for users and roles authorized to perform 'PutFoundationModelEntitlement', 'PutUseCaseForModelAccess', and 'CreateFoundationModelAgreement' actions.\u003c/li\u003e\n\u003cli\u003eUse CloudTrail logs to correlate denied Bedrock attempts with other suspicious IAM activity, such as permission enumeration or credential creation.\u003c/li\u003e\n\u003cli\u003eImplement IAM Service Control Policies (SCPs) to restrict Bedrock management capabilities to specific, hardened administrator roles.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-18T19:37:56Z","date_published":"2026-09-18T19:37:56Z","id":"https://feed.craftedsignal.io/briefs/2026-09-aws-bedrock-unauthorized-access/","summary":"Detection of failed API calls attempting to enable Amazon Bedrock foundation model access, serving as a high-signal indicator for credential boundary-testing and potential LLMjacking.","title":"Detection of Unauthorized Amazon Bedrock Foundation Model Access Attempts","url":"https://feed.craftedsignal.io/briefs/2026-09-aws-bedrock-unauthorized-access/"},{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Amazon Bedrock"],"_cs_severities":["high"],"_cs_tags":["cloud","llm","aws","llmjacking","identity-audit"],"_cs_type":"advisory","_cs_vendors":["Amazon"],"content_html":"\u003cp\u003eLLMjacking involves threat actors gaining access to cloud environments and utilizing stolen long-term IAM credentials (AKIA* access keys) to abuse AI services. In the context of Amazon Bedrock, attackers prioritize identifying available foundation models for potential exploitation to run high-volume or high-cost model inference. This activity is notable because legitimate production workloads utilizing Bedrock typically operate under temporary IAM roles, making the use of long-term user keys for discovery and invocation highly irregular. Defenders should monitor for patterns where the same access key performs enumeration followed immediately by model invocation. This activity indicates a potential compromise of IAM credentials and an attempt to leverage the organization's cloud resources for unauthorized AI model consumption at the account owner's expense.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eLLMjacking can result in significant financial impact due to high-volume model inference costs. Furthermore, it indicates that a threat actor has successfully gained Initial Access via compromised credentials, potentially allowing for broader exploitation of other AWS services such as S3 or Secrets Manager if the IAM user has excessive permissions.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eMonitor AWS CloudTrail logs for the sequence of ListFoundationModels followed by InvokeModel, InvokeModelWithResponseStream, Converse, or ConverseStream by the same access key within 15 minutes.\u003c/li\u003e\n\u003cli\u003ePrioritize auditing of all existing long-term IAM user access keys, enforcing rotation, and migrating Bedrock workloads to IAM roles with short-lived credentials.\u003c/li\u003e\n\u003cli\u003eInvestigate the source IP and user agent associated with any long-term key performing Bedrock operations to identify potential unauthorized access or credential exposure.\u003c/li\u003e\n\u003cli\u003eRestrict the usage of long-term keys for AI services through Service Control Policies (SCPs) where business requirements permit.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-18T19:29:20Z","date_published":"2026-09-18T19:29:20Z","id":"https://feed.craftedsignal.io/briefs/2026-09-llmjacking-bedrock/","summary":"Adversaries are abusing stolen long-term AWS IAM access keys to perform unauthorized reconnaissance and high-cost model inference within Amazon Bedrock.","title":"LLMjacking via Compromised AWS Long-Term IAM Credentials","url":"https://feed.craftedsignal.io/briefs/2026-09-llmjacking-bedrock/"}],"language":"en","title":"CraftedSignal Threat Feed - Llmjacking","version":"https://jsonfeed.org/version/1.1"}