A compromised AI gateway connected to Amazon Bedrock was found communicating with cryptomining infrastructure, exposing how generative AI infrastructure is emerging as a new frontier in the enterprise attack surface.
The incident, investigated by Darktrace and escalated via its Managed Threat Detection service, shows attackers repurposing AI-enabled cloud assets for unauthorized cryptomining.
AI gateways sit between users, applications, and foundation models, centralizing authentication, routing, and policy enforcement for AI workloads.
AI Gateway Compromise Turns Amazon Bedrock Infrastructure
This central role often grants them privileged IAM permissions, making a compromised gateway a high-value pivot point for attackers not just for compute abuse, but potential access to cloud identities, model services, and sensitive prompts.
On June 12, 2026, Darktrace identified suspicious activity from an AWS EC2 instance named “LiteLLM-Proxy,” configured with an instance profile granting access to Amazon Bedrock resources.

While no confirmed link was found to publicly disclosed LiteLLM vulnerabilities, the instance’s role and permissions made it an attractive target.
The investigation revealed a multi-stage compromise:
- Exposed SSH access: The instance had port 22 open to all inbound traffic (0.0.0.0/0), and Darktrace logged a surge of brute-force connection attempts, primarily from IP 145.241.123.102.
- Malware delivery: The host downloaded a 3.42 MB ZIP file from 185.62.1.8 containing XMRig cryptomining malware.
- Mining pool communication: Minutes later, the instance began repeated HTTPS connections on port 443 to pool.hasvault.pro, a pattern consistent with active mining pool activity.
- Detection and escalation: Darktrace’s Enhanced Monitoring model “Compromise / High Priority Crypto Currency Mining” triggered, with Cyber AI Analyst correlating the events into a unified investigation narrative. The SOC escalated the finding via Managed Threat Detection.
- Suspicious IAM activity: A day later, a separate IAM user exhibited anomalous behavior, including an unprecedented “GetSendQuota” call from a Vietnam-based IP (14.176.1.47), unusual AWS CLI usage, failed “InvokeModel” and “ListFoundationModels” attempts against Bedrock, and a “CreateUser” action with a low-entropy username suggesting persistence setup.
While no host-level logs confirmed the exact initial access vector, the convergence of exposed SSH, brute-force attempts, and rapid malware deployment strongly suggests SSH as the likely entry point.
Darktrace noted no confirmed link between the IAM anomalies and the LiteLLM compromise, though the timing raises questions worth further scrutiny.

Cryptomining is a common opportunistic outcome of cloud compromise, but the significance here lies in where it happened an asset sitting at the intersection of cloud infrastructure, identity, and AI operations.
Recent research has flagged AI gateways such as LiteLLM as high-value targets due to their credential and permission aggregation capabilities, though Darktrace found no direct evidence linking this incident to publicly disclosed vulnerabilities in LiteLLM.
The incident reinforces that AI infrastructure can’t be treated as a standalone technology layer. It inherits the same risks as any privileged cloud asset exposed services, weak credentials, and misconfigurations while introducing new stakes around model access and IAM permissions.
Behavioral analysis proved critical in surfacing the compromise before its full scope was understood, underscoring the need for defenders to correlate workload and control-plane telemetry across AI-enabled environments rather than relying on isolated alerts.
Follow us on Google News , LinkedIn and X to Get More Instant Updates. Set Cyberpress as a Preferred Source in Google.