AWS and Operation Bizarre Bazaar Victims: LLMjacking Attack Uses Leaked AWS IAM Key to Steal Paid AI Model Access

AWS and Operation Bizarre Bazaar Victims: LLMjacking Attack Uses Leaked AWS IAM Key to Steal Paid AI Model Access

LLMjacking: How Attackers Hijack AWS Credentials to Exploit Premium AI Models

Security researchers at FortiGuard Labs have uncovered a new cloud attack technique called LLMjacking, where threat actors exploit leaked AWS credentials to monetize access to premium AI models at the victim’s expense.

The attack begins with a compromised long-lived AWS IAM access key carrying AdministratorAccess privileges the highest level of permissions in AWS. Once inside, the attacker creates a new IAM user within the victim’s account and subscribes to high-cost foundation models via AWS Marketplace, generating inference charges billed directly to the compromised organization.

In some cases, attackers also generate Bedrock service-specific API keys, providing an additional, less detectable method to invoke AI models. Unlike traditional cloud attacks such as cryptomining or data exfiltration LLMjacking focuses on abusing the victim’s billing relationship with AWS, turning unauthorized AI usage into a revenue stream.

The financial impact is severe: premium models like Claude 2.x can cost victims over $46,000 per day, while Claude 3 Opus usage can exceed $100,000 daily. Stolen access is often resold as discounted AI chatbot subscriptions on platforms like Telegram and Discord. One tracked operation, Operation Bizarre Bazaar, has been linked to over 35,000 attack sessions across 30+ LLM providers.

Detection is challenging because the malicious API calls originate from valid, permissioned credentials, making them indistinguishable from legitimate usage. FortiGuard Labs notes that conventional monitoring fails to flag this activity, as the traffic itself appears benign.

To mitigate risks, researchers recommend:

"id": "awsgul1788459858",
"linkid": "aws-ai, gulf-cooperation-council---secretariat-general-",
"type": "Cyber Attack",
"date": "9/2026",
"severity": "100",
"impact": "5",
"explanation": "Attack threatening the organization's existence"
{'affected_entities': [{'type': 'Organization'}],
 'attack_vector': 'Compromised AWS IAM access key',
 'description': 'Security researchers at FortiGuard Labs have uncovered a new '
                'cloud attack technique called LLMjacking, where threat actors '
                'exploit leaked AWS credentials to monetize access to premium '
                'AI models at the victim’s expense. The attack begins with a '
                'compromised long-lived AWS IAM access key carrying '
                'AdministratorAccess privileges. Once inside, the attacker '
                'creates a new IAM user within the victim’s account and '
                'subscribes to high-cost foundation models via AWS '
                'Marketplace, generating inference charges billed directly to '
                'the compromised organization. In some cases, attackers also '
                'generate Bedrock service-specific API keys, providing an '
                'additional, less detectable method to invoke AI models. '
                'Unlike traditional cloud attacks such as cryptomining or data '
                'exfiltration, LLMjacking focuses on abusing the victim’s '
                'billing relationship with AWS, turning unauthorized AI usage '
                'into a revenue stream.',
 'impact': {'financial_loss': 'Over $46,000 per day (Claude 2.x), over '
                              '$100,000 daily (Claude 3 Opus)',
            'operational_impact': 'Unauthorized AI model usage billed to '
                                  'victim',
            'revenue_loss': 'Direct billing of high-cost AI model usage',
            'systems_affected': 'AWS accounts with compromised IAM '
                                'credentials'},
 'initial_access_broker': {'backdoors_established': 'New IAM user creation, '
                                                    'Bedrock API keys',
                           'data_sold_on_dark_web': 'Discounted AI chatbot '
                                                    'subscriptions on Telegram '
                                                    'and Discord',
                           'entry_point': 'Compromised AWS IAM access key',
                           'high_value_targets': 'AWS accounts with '
                                                 'AdministratorAccess '
                                                 'privileges'},
 'lessons_learned': 'Detection of LLMjacking is challenging due to the use of '
                    'valid, permissioned credentials, making malicious '
                    'activity indistinguishable from legitimate usage. '
                    'Conventional monitoring may fail to flag this activity.',
 'motivation': 'Financial gain through unauthorized AI model usage',
 'post_incident_analysis': {'corrective_actions': ['Enable AWS CloudTrail and '
                                                   'Bedrock invocation logging',
                                                   'Replace long-lived IAM '
                                                   'keys with short-lived '
                                                   'credentials',
                                                   'Monitor for unusual access '
                                                   'patterns'],
                            'root_causes': 'Exploitation of long-lived AWS IAM '
                                           'credentials with excessive '
                                           'privileges'},
 'recommendations': ['Enable AWS CloudTrail across all accounts to track '
                     'identity creation and marketplace subscriptions',
                     'Activate Bedrock invocation logging for detailed '
                     'request-level visibility',
                     'Replace long-lived, broad-scope IAM keys with '
                     'short-lived, role-assumed credentials',
                     'Monitor for newly created identities, unfamiliar IPs, or '
                     'unusual access patterns'],
 'references': [{'source': 'FortiGuard Labs'}],
 'response': {'enhanced_monitoring': 'AWS CloudTrail and Bedrock invocation '
                                     'logging',
              'remediation_measures': ['Enabling AWS CloudTrail across all '
                                       'accounts',
                                       'Activating Bedrock invocation logging',
                                       'Replacing long-lived IAM keys with '
                                       'short-lived, role-assumed credentials',
                                       'Monitoring for newly created '
                                       'identities, unfamiliar IPs, or unusual '
                                       'access patterns'],
              'third_party_assistance': 'FortiGuard Labs'},
 'threat_actor': 'Operation Bizarre Bazaar',
 'title': 'LLMjacking: How Attackers Hijack AWS Credentials to Exploit Premium '
          'AI Models',
 'type': 'Cloud Credential Abuse',
 'vulnerability_exploited': 'Long-lived AWS IAM credentials with '
                            'AdministratorAccess privileges'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.