Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

New AI-Powered Threat Allows Hackers to Gain AWS Admin Access in Minutes

## Cybersecurity: AI-Driven Cloud Intrusion

Cybersecurity: AI-Driven Cloud Intrusion

A recent sophisticated cyberattack targeted an AWS environment, utilizing AI automation to achieve administrative control in less than 10 minutes. The attack commenced with the discovery of exposed credentials in public Simple Storage Service (S3) buckets, which were named using AI-related terminology.

The attackers employed a method known as LLMjacking, leveraging Large Language Models (LLMs) for automated reconnaissance and malicious code generation. The Sysdig Threat Research Team (TRT) documented this incident, noting the rapid escalation from initial access to administrative privileges.

During the attack, Python code was injected into an existing AWS Lambda function. This script, featuring Serbian comments, enabled the attackers to list all Identity and Access Management (IAM) users and create new administrative access keys.

Lateral Movement and Resource Exploitation

After securing administrative access, the attackers conducted lateral movements across 19 AWS principals, using a combination of compromised accounts and assumed roles. A Terraform module named terraform-bedrock-deploy.tf was identified, designed to deploy a backdoor Lambda function for generating Bedrock credentials.

A recent sophisticated cyberattack targeted an AWS environment, utilizing AI automation to achieve administrative control in less than 10 minutes.
Lucas Norwood · Thehackingpost

The primary objective was resource theft, with attackers exploiting Amazon Bedrock to execute multiple high-end AI models, effectively stealing compute time. They also attempted to launch expensive GPU instances, successfully deploying a p4d.24xlarge instance, potentially costing the victim approximately $23,600 per month.

A JupyterLab server was installed on this instance, providing a backdoor for continuous access to computing resources even if AWS credentials were revoked.

This incident underscores the threat posed by AI-driven attacks capable of executing complex operations swiftly. The following mitigation strategies are recommended:

Advertisement

Eliminate Long-Term Credentials: Use IAM roles with temporary credentials instead of static keys. Secure S3 Buckets: Ensure that S3 buckets containing sensitive data are not publicly accessible. Restrict Lambda Permissions: Apply the principle of least privilege, avoiding broad permissions such as UpdateFunctionCode unless necessary. Monitor Bedrock Usage: Set up alerts for unexpected AI model invocations.

Automating detection processes is essential to counter the reduced response time due to AI-driven attack chains.

Based on reporting by GBHackers.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories