Hackers Actively Exploit AI Deployments as 91,000+ Attack Sessions Are Detected

Security researchers have documented a surge in coordinated attacks targeting artificial intelligence infrastructure, with more than 91,000 malicious sessions recorded between October 2025 and January 2026.

The analysis reveals two distinct threat campaigns that systematically exploit the expanding surface area of AI deployments, ranging from server-side request forgery vulnerabilities to methodical reconnaissance of large language model endpoints.

GreyNoise’s honeypot infrastructure captured the data, and threat intelligence customers have been notified via Executive Situation Reports (SITREPs) containing indicators of compromise and actionable defense strategies.

The SSRF Campaign: Forcing Servers to Phone Home

The first campaign exploited server-side request forgery (SSRF) vulnerabilities, techniques that manipulate servers into making unauthorized outbound connections to attacker-controlled infrastructure.

This corroborates and extends Defused’s findings.
This corroborates and extends Defused’s findings.

The operation targeted two primary vectors: Ollama’s model pull functionality and Twilio SMS webhook integrations.

Attackers injected malicious registry URLs into Ollama deployments to force HTTP requests to adversary infrastructure, while simultaneously manipulating MediaUrl parameters in Twilio integrations to trigger unwanted outbound connections.

The campaign peaked over the Christmas period, generating 1,688 sessions within 48 hours.

Analysis of the attack infrastructure revealed consistent fingerprints across 62 source IPs in 27 countries, indicating VPS-based tooling rather than traditional botnets.

The predominant use of ProjectDiscovery’s OAST (Out-of-band Application Security Testing) infrastructure for callback validation, a technique typically associated with security researchers, suggests the operations may involve grey-hat actors or bug bounty hunters operating at scale.

More concerning is the second campaign, which launched on December 28, 2025, targeting 73+ LLM model endpoints.

Two IP addresses orchestrated 80,469 sessions over eleven days, conducting systematic reconnaissance of misconfigured proxy servers that might expose access to commercial AI APIs.

The attack tested both OpenAI-compatible and Google Gemini API formats across all major model families: GPT-4o, Claude, Llama, DeepSeek, Gemini, Mistral, Qwen, and Grok.

The probes used innocuous queries such as “How many states are there in the United States?” and standard fingerprinting techniques to identify responsive models without triggering security alerts.

The infrastructure analysis traced the campaign to two dedicated IPs with extensive CVE exploitation histories, resulting in more than 4 million sensor hits.

The operators demonstrated professional capability, with attack patterns consistent with reconnaissance feeding into larger exploitation pipelines.

Organizations should implement strict model pull restrictions, configure egress filtering to prevent SSRF callbacks, and deploy rate-limiting for suspicious ASNs.

DNS blocking of OAST callback domains and alerts for rapid multi-endpoint probing queries provide immediate detection mechanisms for ongoing threats.

Follow us on Google News , LinkedIn and X to Get More Instant UpdatesSet Cyber Press as a Preferred Source in Google.

AnuPriya
AnuPriya
Any Priya is a cybersecurity reporter at Cyber Press, specializing in cyber attacks, dark web monitoring, data breaches, vulnerabilities, and malware. She delivers in-depth analysis on emerging threats and digital security trends.

Trending News

Related Stories