News · curated 9 Jul 2026
Hackers Compromise AWS AI Gateway Connected to Amazon Bedrock to Deploy XMRig Cryptominer
First reported · updated · 3 reports darktrace.com
Coverage timeline
Why it matters
AI gateways like LiteLLM-Proxy hold privileged access to foundation-model infrastructure such as Amazon Bedrock, making them high-value targets whose compromise can expose model access and cloud credentials in addition to enabling cryptomining.
Darktrace disclosed an incident in which attackers compromised an AWS EC2 instance running LiteLLM-Proxy — an AI gateway centralizing access to Amazon Bedrock foundation models through a privileged IAM role — and deployed XMRig cryptomining malware. The instance had SSH port 22 exposed to all inbound traffic (0.0.0.0/0) and was hit by brute-force attempts, primarily from IP 145.241.123[.]102.