Darktrace reported that attackers compromised a publicly exposed AWS EC2 instance running LiteLLM as an AI gateway to Amazon Bedrock and used it to deploy the XMRig cryptominer. Investigators observed internet-exposed SSH on port 22, repeated short inbound connection attempts, an HTTP download from 185.62.1.8 consistent with malware delivery, and outbound HTTPS traffic to the Monero mining pool pool.hasvault.pro. The host, identified as LiteLLM-Proxy, was later shut down, and Darktrace assessed brute-force or other SSH-based access as a plausible initial intrusion path.
The incident drew attention because the compromised system was not just a compute node but an AI gateway with an instance profile tied to Bedrock resources, potentially exposing API access, IAM permissions, prompts, logs, model outputs, and downstream application workflows. Darktrace warned that such gateways can concentrate access to foundation models, proprietary data, and broader cloud resources, making them attractive targets for credential theft, abuse of AI inference services, persistence in AWS, and lateral movement. The firm recommended limiting IAM privileges, removing internet exposure from management interfaces, using short-lived credentials, segmenting AI infrastructure, and monitoring AI-specific administrative activity.

Map this exposure pattern across your cloud, code, and identities.
4 events from the most recent confirmed update back to the earliest known activity.
The compromised EC2 instance was later taken offline following the cryptomining activity. The shutdown ended activity on the exposed AI gateway connected to Amazon Bedrock.
After the compromise, the attacker downloaded and installed XMRig from 185.62.1.8 and the host made repeated outbound HTTPS connections to the mining pool pool.hasvault.pro. Darktrace classified the activity as a high-priority cryptocurrency mining incident.
Darktrace investigated an incident in which a publicly exposed AWS EC2 instance running LiteLLM and connected to Amazon Bedrock was compromised. The attacker likely gained access via SSH brute-force attempts against port 22, though Darktrace could not confirm a successful login.
The day after the EC2 cryptomining incident, Darktrace observed unusual AWS CLI activity from a Vietnam-based IP address, failed Amazon Bedrock-related commands, and an attempted CreateUser action. Darktrace said it could not conclusively link this IAM activity to the compromised instance, but noted it suggested possible credential misuse or persistence attempts.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See where this exposure pattern shows up across your cloud, code, supply chain, and non-human identities.
5 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcehackread.com
Open sourcedarkreading.com
Open sourcedarktrace.com
Open sourcedocs.litellm.ai
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.