Threat actors are posing as AI crawlers to hunt for exposed credentials
ID: 901cec33-91f1-5994-acbf-86f04be59882
STIX ID: report--901cec33-91f1-5994-acbf-86f04be59882
Feed Name: Help Net Security
Threat Score
GreyNoise observed a coordinated scanning campaign that forges AI crawler user-agent strings (OpenAI, Anthropic, Google, Perplexity and Amazon) from 824 IPs spread across ~795 /24 networks to request sensitive files like .env, .env.production, .aws/credentials and private key stores; none of the IPs matched vendor-published ranges and GreyNoise could not confirm successful file retrieval, but it published the 824 addresses and targeted paths for defenders to check.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
