logo

LLMjacking evolved: Attackers are using stolen AI compute to build offensive agentic tools

ID: e5f2d8a4-ee64-5d82-bf97-5c107d37b6b9

STIX ID: report--e5f2d8a4-ee64-5d82-bf97-5c107d37b6b9

Feed Name: Sysdig Blog

Threat Score
75/100

Date Published: 2026-06-17

Date Updated: 2026-06-17

...
...

On June 12–14, 2026, Sysdig Threat Research captured a threat actor using an unauthenticated, internet-exposed Ollama model server as the reasoning engine for an automated, multi-stage offensive tool (VAPT). The framework issues strictly structured prompts for service fingerprinting, vulnerability matching, web reconnaissance, exploit/POC synthesis (including blind SQLi), credential extraction, and orchestration to confirm RCE using marker-bracketed probes (e.g., echo VAPTb3gin; id; echo VAPTfin). The actor tested and iterated the tool against private practice ranges while rotating residential IPs; the report includes full pipeline prompts, requested model names, IoCs (IP addresses, marker strings, command templates), and concrete defensive recommendations to restrict network exposure, require authentication, monitor inference endpoints, and audit for exposed model servers.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.