Hackers Exploit Misconfigured Proxies to Access Large Language Model Services
- Securityish
- Threats & Incidents
Quick Summary
The Securityish Brief
Threat actors have been actively hunting for misconfigured proxy servers to access paid LLM services, with campaigns starting in late December. GreyNoise reports that over 73 LLM endpoints have been probed, resulting in more than 80,000 sessions. The attackers utilized harmless queries to avoid triggering security alerts while testing access to various AI models.
One significant operation began in October and continues to this day, exploiting server-side request forgery (SSRF) vulnerabilities. This campaign has seen a spike in activity, particularly around Christmas, with 1,688 sessions recorded over 48 hours. The attackers employed Ollama’s model pull functionality to inject malicious URLs, showcasing a sophisticated approach to their operations.
GreyNoise’s Ollama honeypot detected a total of 91,403 attacks linked to two distinct campaigns. The second campaign, which started on December 28, focused on identifying exposed or misconfigured LLM endpoints, generating 80,469 sessions in just 11 days. The probing targeted models from major providers, including OpenAI, Anthropic, Meta, DeepSeek, Google, Mistral, Alibaba, and xAI.
The scanning infrastructure used by the attackers is associated with broader vulnerability exploitation activities, suggesting that this enumeration effort is part of organized reconnaissance. While no direct exploitation or data theft has been reported, the scale of the activity indicates malicious intentions.
Implications for Cybersecurity
This ongoing campaign highlights significant risks for organizations using LLM services. Misconfigured proxies can expose sensitive data and allow unauthorized access to AI models. Organizations should be vigilant about their configurations and ensure that only trusted registries are allowed for model pulls.
To mitigate risks, it is crucial to implement egress filtering and block known OAST callback domains at the DNS level. Rate-limiting suspicious ASNs and monitoring for automated scanning tools can also help defend against these types of attacks.
As threat actors continue to probe for vulnerabilities, organizations must prioritize security measures and regularly review their configurations to prevent unauthorized access to their LLM services.
Key Takeaways
- Restrict Ollama model pulls to trusted registries to prevent unauthorized access.
- Implement egress filtering to control outbound traffic and block potential threats.
- Monitor for JA4 network fingerprints linked to automated scanning tools.
- Rate-limit suspicious ASNs to reduce the risk of enumeration attacks.
- Regularly review and update configurations to ensure they meet security best practices.
Key Terms & Concepts
- Server-Side Request Forgery (SSRF): In this article, SSRF refers to a vulnerability that allows an attacker to force a server to connect to an external infrastructure controlled by them.
- OAST (Out-of-band Application Security Testing): OAST is a technique used in vulnerability assessments to test for security weaknesses by monitoring external callbacks.
- LLM (Large Language Model): LLM refers to advanced AI models capable of understanding and generating human-like text, often used in various applications.
Your 5-Minute Securityish Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.
Securityish
Securityish explains cybersecurity, scams, data breaches, and privacy risks in simple language so you know what’s happening and how to protect yourself.
Navigation
Your 5-Minute Cybersecurity Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.