HomeSecurityCriminals seize and resell AI infrastructure

Criminals seize and resell AI infrastructure

For years, CSOs have worried about their IT infrastructure being used for unauthorized cryptocurrency mining. Now, researchers say they should start worrying about criminals seizing and reselling access to exposed corporate AI infrastructure. In a report released Wednesday, researchers at Pillar Security say they have uncovered large-scale campaigns targeting exposed endpoints of large language models (LLMs) and MCPs — for example, an AI-powered support chatbot on a website.

See also: Weaknesses of ChatGPT integration with Apple Health

AI infrastructure
Criminals seize and resell AI infrastructure

“I think it’s concerning,” said report co-author Ariel Fogel. “What we’ve uncovered is a real criminal network where people are trying to steal your credentials, your ability to use LLMs and your calculations, and then resell it.” “It depends on your application, but you should act quickly to block this kind of threat,” added co-author Eilon Cohen. “After all, you don’t want your valuable resources being used by others. If you develop something that has access to critical data, you should act now.”

Kellman Meghu, chief technology officer at Canadian incident response firm DeepCove Security, said this campaign “will only grow in scale with devastating consequences. The worst part is the low level of technical knowledge required to exploit it.”

In the last two weeks alone, researchers' honeypots recorded 35,000 attack sessions looking for exposed AI infrastructure.

The campaigns appear to be run by a small group. The goals: To steal compute resources for use by unauthorized LLM applications, resell access to APIs at discounted prices through criminal marketplaces, extract data from LLM context windows and chat history, and access internal systems via compromised MCP servers. Researchers have so far identified two campaigns: One, dubbed Operation Bizarre Bazaar, targets unprotected LLMs. The other campaign targets Model Context Protocol (MCP).

It’s not hard to find these exposed endpoints. The threat actors behind the campaigns are using well-known tools: the IP search engines Shodan and Censys. At risk: Organizations that operate self-hosted LLM infrastructure (such as Ollama, software that processes a request to the LLM model behind an application, vLLM, similar to Ollama but for high-performance environments, and local AI implementations) or those that deploy MCP servers for AI integrations.

See also: When does Apple plan to unveil the new Siri with Gemini

Criminals seize and resell AI infrastructure
Criminals seize and resell AI infrastructure

Targets include: exposed endpoints on default LLM shared service ports, unauthorized access to APIs without proper access controls, development/test environments with public IP addresses, MCP servers connecting LLMs to file systems, databases, and internal APIs. Common misconfigurations exploited by these threat actors include: Ollama running on port 11434 without authentication, OpenAI-compatible APIs on port 8000 exposed to the internet, MCP servers accessible without access controls, development/test AI infrastructure with public IPs, production chatbot endpoints (customer support, sales bots) without authentication or rate limiting.

Defenders should treat AI infrastructure with the same rigor as APIs or databases, starting with authentication, telemetry, and threat modeling early in the development cycle. CSOs and information security leaders need to act quickly, especially if an LLM has access to critical data.

So far, the researchers said, those buying access appear to be people building their own AI infrastructure and trying to save money, as well as people involved in online gaming. Threat actors may not only be stealing AI access from fully developed applications, the researchers added.

A developer trying to pioneer an app who inadvertently fails to secure a server could be a victim of credential theft as well. Joseph Steinberg, a US-based AI and cybersecurity expert, said the report is another illustration of how new technology like artificial intelligence creates new risks and the need for new security solutions beyond traditional IT controls.

CSOs should ask themselves whether their organization has the skills they need to safely develop and protect an AI project, or whether the task should be outsourced to a provider with the necessary expertise.

Pillar Security said CSOs with external LLMs and MCP servers should enable authentication on all LLM endpoints and AI infrastructure. Requiring authentication eliminates opportunistic attacks. Organizations should verify that Ollama, vLLM, and similar services require valid credentials for all requests. Monitor the exposure of MCP servers. MCP servers should never be directly accessible from the internet. They should also verify firewall rules, review cloud security groups, verify authentication requirements, and block known malicious infrastructure. Add the 204.76.203.0/24 subnet to deny lists.

See also: Claude AI for iPhone now connects to Apple Health in the US

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Criminals seize and resell AI infrastructure
Criminals seize and resell AI infrastructure

For the MCP identification campaign, block AS135377 domains . Implement rate limiting. Stop exploit bursts. Deploy WAF/CDN rules for AI traffic patterns. Review the exposure of production chatbots. Every customer-facing chatbot, sales assistant, and internal AI agent should have security controls in place to prevent abuse. Don’t give up. Despite the number of headlines in the past year about AI vulnerabilities, Meghu said the answer is not to abandon AI, but to maintain strict controls on its use.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS