News · curated 9 Jul 2026

Hackers Compromise AWS AI Gateway Connected to Amazon Bedrock to Deploy XMRig Cryptominer

Coverage timeline

discovered darktrace.com primary 9 Jul 2026siliconangle.comdarkreading.com 10 Jul 2026gbhackers.com

Why it matters

AI gateways like LiteLLM-Proxy hold privileged access to foundation-model infrastructure such as Amazon Bedrock, making them high-value targets whose compromise can expose model access and cloud credentials in addition to enabling cryptomining.

Darktrace disclosed an incident in which attackers compromised an AWS EC2 instance running LiteLLM-Proxy — an AI gateway centralizing access to Amazon Bedrock foundation models through a privileged IAM role — and deployed XMRig cryptomining malware. The instance had SSH port 22 exposed to all inbound traffic (0.0.0.0/0) and was hit by brute-force attempts, primarily from IP 145.241.123[.]102.