logo

LLMjacking via Laravel exploitation (Incident)

ID: 39fff8ee-d4ce-5ed5-afb3-a6f1e6c9cefe

STIX ID: report--39fff8ee-d4ce-5ed5-afb3-a6f1e6c9cefe

Feed Name: Wiz Cloud Threat Landscape

Threat Score
70/100

Date Published: 2024-05-06

Date Updated: 2026-05-01

Author: [email protected] (Wiz Threat Research)

...
...

Threat actors exploited a vulnerable, publicly exposed Laravel instance (CVE-2021-3129) to steal cloud credentials, enumerate permissions across AWS/Azure/GCP, and attempt unauthorized access to LLM services (notably Anthropic Claude). They used an open-source reverse proxy (OAI Reverse Proxy) to operate multiple compromised accounts and validated access via the InvokeModel API, apparently to monetize access while minimizing detection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.