AWS documented an incident-response scenario in which an attacker exploited a server-side request forgery (SSRF) flaw in an EC2-hosted web application to retrieve temporary credentials for the instance's attached webdev IAM role through IMDSv1. The attacker enumerated the role's permissions, established an AWS Management Console session without MFA, pivoted from us-east-1 to us-east-2, and enumerated Amazon Bedrock foundation models. The actor then invoked Amazon Nova Pro through the Converse API, resulting in unauthorized token consumption.
The activity was enabled by IMDSv1 exposure, an overprivileged EC2 role with unnecessary cross-Region Bedrock permissions, and missing MFA, with inconsistent regional logging and controls potentially limiting detection. AWS advises remediating the SSRF flaw, requiring IMDSv2 for EC2 metadata access, revoking and investigating use of the compromised role, reviewing CloudTrail across all Regions, restricting Bedrock permissions, and enabling Bedrock model-invocation logging to determine whether prompts or generated outputs were exposed.

Map this exposure pattern across your cloud, code, and identities.
5 events from the most recent confirmed update back to the earliest known activity.
The webdev role invoked the Amazon Nova Pro model (amazon.nova-pro-v1:0) through the Bedrock Converse API in us-east-2. The unauthorized invocation consumed 944 input tokens and generated 126 output tokens.
Using the previously established console session, the webdev role called Amazon Bedrock ListFoundationModels in us-east-2, conducting read-only reconnaissance in a different AWS Region.
The assumed webdev role successfully performed a ConsoleLogin in us-east-1 from IP address 75.3.231.105 using a Windows 10 browser. The login recorded MFAUsed as "No" and mfaAuthenticated as false.
The assumed webdev role attempted to create an IAM user named "adm1n" in us-east-1 using AWS CLI. AWS denied the CreateUser request because the role lacked iam:CreateUser permission.
A threat actor exploited an SSRF vulnerability in an EC2-hosted web application to access IMDSv1 and obtain temporary credentials for the instance's attached webdev IAM role.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See where this exposure pattern shows up across your cloud, code, supply chain, and non-human identities.
4 references tracked. Mallory keeps watching after this page renders.
infosec.pub
Open sourceinfosec.pub
Open sourceaws.amazon.com
Open sourcedocs.aws.amazon.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.