datadog-security-labs · Crawled Sep 19, 2026
Attacker infrastructure, but vibe-coded: tracking the evolution of credential harvesting platforms
1 IoCs 2 CVEs
Read original article ↗
AI Summary
Datadog Security Research has identified two credential harvesting platforms, Loot and UltraVault, which are used to inventory, validate, and exploit stolen credentials, including API keys for cloud and AI services. The platforms are accessible without authentication and support automated validation and post-exploitation actions, such as re-probing credentials and recommending local privilege escalation exploits. The attacker infrastructure has been observed abusing Amazon Bedrock through API calls like GetCallerIdentity, ListFoundationModels, and InvokeModel, indicating active exploitation of compromised AWS credentials, including both long-term and temporary STS credentials.
AI-extracted · verify before operational use
Extracted Entities 2 found
Indicators of Compromise 1 extracted
| Type | Value | Detail |
|---|---|---|
| IP | associated | Details → |
MITRE ATT&CK TTPs 36 techniques
T1001.002 Steganography · Command And Control T1021.004 SSH · Lateral Movement T1053.005 Scheduled Task · Execution T1059 Command and Scripting Interpreter · Execution T1059.001 PowerShell · Execution T1059.004 Unix Shell · Execution T1070.001 Clear Windows Event Logs · Defense Evasion T1071.001 Web Protocols · Command And Control T1078 Valid Accounts · Defense Evasion T1082 System Information Discovery · Discovery T1090 Proxy · Command And Control T1098 Account Manipulation · Persistence T1110 Brute Force · Credential Access T1133 External Remote Services · Persistence T1190 Exploit Public-Facing Application · Initial Access T1203 Exploitation for Client Execution · Execution T1210 Exploitation of Remote Services · Lateral Movement T1211 Exploitation for Defense Evasion · Defense Evasion T1218 System Binary Proxy Execution · Defense Evasion T1485 Data Destruction · Impact T1558.003 Kerberoasting · Credential Access T1566 Phishing · Initial Access T1569 System Services · Execution T1570 Lateral Tool Transfer · Lateral Movement T1571 Non-Standard Port · Command And Control T1572 Protocol Tunneling · Command And Control T1589 Gather Victim Identity Information · Reconnaissance T1595 Active Scanning · Reconnaissance T1599 Network Boundary Bridging · Defense Evasion T1650 Acquire Access · Resource Development T1021 Remote Services · Lateral Movement T1027 Obfuscated Files or Information · Defense Evasion T1046 Network Service Discovery · Discovery T1071 Application Layer Protocol · Command And Control T1105 Ingress Tool Transfer · Command And Control T1505.003 Web Shell · Persistence