// threat intel // llmjacking // credential harvesting
TL;DR Datadog Security Labs spent the summer watching two credential harvesting panels, Loot and UltraVault. Both were built with an LLM. Both were reachable with no login. One of them tracks 42,286 stolen secrets and treats your AI API keys as a product line. The code is sloppy. The operation works anyway.
Somebody prompted this into existence
The crooks have the same problem your product team has. They shipped an internal tool in a hurry, it has emoji in the menus, and nobody put a login page in front of it.
That is roughly what Datadog Security Labs published on 18 September. Since July 2026 their research team has been monitoring a set of credential harvesting platforms that inventory stolen secrets, validate them and then act on them. Two stand out, and at times both were served from the same host. Datadog calls them Loot and UltraVault.
The first read is funny. The second one is not.
Loot: the junk drawer
Loot is the simple one. A searchable index of stolen secrets, all in plaintext, browsable by category and searchable by victim domain. There is a validate button. That is most of the product.
The parsing is bad. Datadog says the platform regularly misfiles credentials and that the credential field often holds strings that are not credentials at all. Plenty of entries are real though.
One of the biggest categories is AI. 1,778 records across 15 provider labels, 196 of them live. OpenAI leads with 699 keys and 93 live. Gemini has 666 with 55 live. Anthropic has 114 with 10 live. For an OpenAI key the panel lists which models it can reach, picks the best one and confirms whether credits remain.
The panel checks your balance before anyone bothers stealing from you.
UltraVault: the ops console
UltraVault does the same inventory job and then bolts an operations layer on top. This is where it stops being a joke.
It knows how the creds arrived
Targets are grouped under named exploitation chains. react2shell maps to CVE-2025-55182. wp2shell, xss2shell and joomla2shell each map to CVEs from this year. There is a fifth one just called deep.
It reassembles AWS keys
An endpoint at /api/pairs correlates access key IDs and secret keys that were collected separately and scattered across different dumps. A second one, /api/actions/aws_pair, submits the rebuilt pair and shows the account ID, ARN and region. Half a key in one leak and half in another used to be a near miss. Now a button fixes that.
It tells the operator what to fire next
Click a victim domain and a side panel walks through 14 local privilege escalation bugs with go and no-go verdicts for that specific host, ending in one recommended exploit. There are actions to re-open WordPress shells that died, and a tab for hosting panels that lists credentials the operator minted on the box. Datadog's screenshot shows a cPanel host on port 2083.
The react2shell chain also has a cloud pivot. From a compromised Node process it asks for metadata endpoints, Kubernetes reachability, AWS SDK access, account ID and role. Datadog is careful here and so should we be. The frontend shows the capability exists. They could not confirm it succeeded. Of the 17 capabilities they reviewed, only about a third are provable from frontend source alone.
The tells
How do you know an LLM wrote it? Datadog points at emoji-labelled action menus and AI-generated exploitation recommendations. Loot's broken parser fits the picture too.
And the big one. A console full of stolen credentials with no authentication, on the open internet. That is the same finding I would write up against any weekend-built internal app. Their SDLC has no AppSec review either.
Why the slop does not save you
Do the maths. 2.7% of 42,286 is around 1,140 working secrets. Nobody running this needs a good hit rate. Both panels sort keys into live, pending and dead and keep re-probing what they already hold, so the inventory cleans itself.
The LLM made the boring part cheap. Glue code and a UI that tracks targets used to take a crew with a developer in it. Skill is now optional. Datadog makes the same point in its conclusion: Loot breaks easily, UltraVault ships as a working console, and both came out of the same lowered barrier.
This is also the second sighting. Google's threat intel team documented an exposed framework it dubbed Recon managing over 23,800 harvested secrets. Different platform, same pattern.
What it looks like in your CloudTrail
Datadog's investigation started because the IP hosting both dashboards was seen validating Amazon Bedrock access with stolen AWS keys. The sequence is consistent. Confirm the identity works, list what it can reach, start calling models.
sts:GetCallerIdentity
bedrock:ListFoundationModels
bedrock:ListInferenceProfiles
bedrock:InvokeModel # dozens of calls, several regions, under a minute
The InvokeModel bursts first went at multiple Anthropic model versions. From September they also hit DeepSeek, Mistral, Kimi and GLM-5.
Two user agents are worth a rule. One is Boto3 with kali-cloud sitting in the OS string. The other is a bare Python-urllib/3.13 with no SDK at all.
One more detail that should bother you. The same host was validating temporary STS credentials, the ones with an ASIA prefix and an AssumedRole identity. "We only use short-lived creds" does not hold up if the process leaking them is still exploitable.
What I would do on Monday
- Deny Bedrock by SCP in every account and region that has no business using it. You cannot be LLMjacked through a service that is switched off.
- Alert on Bedrock discovery from long-term keys. An
AKIAkey callingListFoundationModelsis almost never legitimate. - Alert on
InvokeModelacross several regions inside a minute. Real workloads do not spray regions. - Flag the lazy user agents.
kalior barePython-urllibagainst AWS APIs. It will get evaded eventually. It catches people today. - Patch the front door. React2Shell and the WordPress chains are how the secrets get into these panels in the first place.
- Treat AI provider keys like cloud keys. Inventory them, rotate them and put a spend cap on every one. A key with credits on it is merchandise.
- Enforce IMDSv2 with a hop limit of 1 where your workloads allow it, so a popped container has a harder time reaching instance credentials.
Datadog chose not to publish indicators, to protect the victims whose credentials are sitting in those panels. Fair call. It means behaviour-based detection is all you get.
Verdict. The vibe-coded panel is ugly and it leaks. It also tracks tens of thousands of secrets, keeps re-checking them and tells a mediocre operator which exploit to fire next. We keep telling developers that ugly tooling that ships beats elegant tooling that never does. The other side was listening.
No comments:
Post a Comment