- Datadog Security Labs found tools that check whether stolen AWS keys can run Amazon Bedrock AI models, using a tiny test request.
- The test costs the attacker very little. Datadog says detecting it early helps avoid a larger bill later.
- Leaders should ask which identities can call Bedrock, and whether anyone would notice a first-ever call from a new source.
A stolen cloud key is not just a key. To the person selling it, it is a grade. Datadog Security Labs reports that attackers also grade stolen AWS keys by one more question: can this key run AI models?
That changes what a leaked key is worth. It also changes what a defender should look for in their logs.
What Datadog found
Datadog's researchers describe a repeatable test for stolen AWS credentials that reach Amazon Bedrock, AWS's service for running AI models. They found it in several places.
The first is a credential harvesting platform called KMON_NOC. Datadog has observed it targeting customers since August 31, 2026. Hosts tied to the platform probed for credentials at more than 80 Datadog Cloud SIEM customers.
Datadog could not see KMON_NOC's validation logic or its AWS activity. The findings come from a public JavaScript bundle the portal loads. That code shows fields, filters and statistics built around Bedrock access.
The researchers say this treats Bedrock as a separate capability. The code also pulls out AWS_BEARER_TOKEN_BEDROCK, the variable that holds Bedrock API keys. Datadog calls these inferences, not confirmed behavior.
How the test works
Datadog also analyzed two unrelated Python scripts found on VirusTotal. Both process lists of credentials, identify the AWS principal behind each one, and test Bedrock across several regions.
One of the two scripts, analyzed in detail by Datadog, works in steps. The other differs mainly by lacking the GetCredits check described below.
First, the script asks AWS's identity service who the key belongs to. This call is named GetCallerIdentity. A failure means the key is treated as unusable.
Second, it asks Bedrock in each region which models exist, using ListFoundationModels. That tells the attacker what the key can see.
Third, it sends a request through Bedrock's Converse call. The prompt is the word "ping". The reply is capped at four tokens, which keeps the cost of each test tiny. Any successful reply counts as proof the key works.
The analyzed script defaults to smaller, cheaper models. It also has a mode that targets Anthropic Claude models. That mode checks for an error meaning the account has not yet submitted Anthropic's required use case details.
That script goes one step further when an option is switched on. It calls a billing function, GetCredits, to read promotional credit balances. Datadog says this lets the attacker judge a key's financial value as well as its usability.
Why a cheap test matters
The test costs the attacker close to nothing. Any charges for later use of the key fall on the account owner. A key that passes can be used, or sold. Datadog cites Unit 42 research on resellers who run proxies and sell access to commercial AI models below retail price. Those services depend on credentials that are stolen and shared.
Datadog says attackers have used the same logic for years on AWS email and SMS services. They check sending limits, and the answer affects the resale price. AI access, in Datadog's account, is checked in a similar way.
Datadog does not claim every probe ends in a large charge. Its view is that a light check like this may be an early step toward more costly misuse of the key.
In most of those cases, Datadog saw failed ListFoundationModels calls across several regions and nothing after. In one case, model listing succeeded. Converse calls for Anthropic models were then denied. Datadog says it cannot link the analyzed script to this telemetry.
What to ask your team
Small probes are what to look for. Datadog advises investigating unexpected Bedrock activity, especially from a new source or from an identity with no history of AI use. It also says to watch both Converse and InvokeModel calls.
Start with these questions.
Which identities in our accounts can call Bedrock, and do any of them have no business reason to? If a long-term key with no AI history lists models in five regions, who is told?
Do we alert on new Bedrock access keys that never expire? Datadog lists that as one of its detection rules.
Datadog also published IP addresses seen in this pattern since August 31. They include residential proxies, VPNs and hosting providers, so Datadog advises using them only alongside the AWS activity described in its post.
A four-token request is easy to overlook. It is also how a stolen key gets its value assessed.
Produced by the WebPulse Newsroom with AI assistance from the original reporting credited below, and checked against that source by our editorial review. How we use AI.
Original reporting: Datadog Security Labs.





