A significant internet-wide scanning campaign was observed over the 2025 Christmas holiday, where a single operator systematically probed for vulnerable systems using more than 240 different exploits. The attacker leveraged ProjectDiscovery's Interactsh platform and Nuclei scanner at scale, confirming vulnerabilities via out-of-band callbacks and building a fresh inventory of exploitable systems. This reconnaissance activity is believed to support the Initial Access Broker (IAB) ecosystem, where access to compromised networks is sold to ransomware operators, setting the stage for targeted attacks throughout 2026. The campaign was traced to two IP addresses and involved over 57,000 unique OAST subdomains, highlighting the industrialization of vulnerability scanning and the supply chain of ransomware operations.
In parallel, threat actors have been observed actively targeting large language model (LLM) deployments, with campaigns exploiting server-side request forgery (SSRF) vulnerabilities and systematically mapping AI infrastructure. GreyNoise's honeypot infrastructure recorded over 91,000 attack sessions, including a dramatic spike in activity during the Christmas period, with attackers using similar OAST infrastructure and automation tooling as seen in the broader scanning campaign. These activities underscore the growing threat posed by automated, large-scale reconnaissance and exploitation efforts, which are increasingly targeting both traditional IT assets and emerging AI platforms, and are likely to drive a new wave of intrusions and ransomware attacks in 2026.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
On January 8, 2026, GreyNoise published details of the December 25-28 reconnaissance campaign, saying the operation scanned for more than 240 exploit types and likely served as groundwork for 2026 ransomware attacks. It advised organizations to review logs for the identified IPs and OAST domains because successful callbacks may indicate confirmed vulnerabilities now potentially for sale.
By January 8, 2026, GreyNoise disclosed that its Ollama honeypots had recorded more than 91,000 attack sessions from October 2025 through January 2026, documenting both SSRF exploitation attempts and large-scale endpoint enumeration. The company warned that exposed LLM endpoints were likely already being prepared for future exploitation.
Between December 25 and 28, 2025, the same holiday scanning operation entered a second wave that added more exploit templates and continued cataloging exploitable internet-facing systems. GreyNoise assessed the timing as likely intended to take advantage of reduced holiday security staffing.
On December 25, 2025, a single operator began an internet-wide reconnaissance campaign using two CTG Server Limited IP addresses to scan for hundreds of exploits. The activity used Nuclei and Interactsh OAST domains to confirm vulnerable systems, behavior consistent with an initial access broker collecting targets.
Between late 2025 and January 2026, two threat-actor IPs systematically enumerated more than 73 LLM model endpoints across major providers including OpenAI, Anthropic, Meta, Google, Mistral, Alibaba, DeepSeek, and xAI. GreyNoise linked the infrastructure to known CVE-exploitation activity and said the enumeration campaign generated more than 80,000 sessions in 11 days.
GreyNoise observed the start of campaigns against AI deployments in October 2025, with attackers probing Ollama and related integrations. One campaign exploited SSRF paths in Ollama model pulls and Twilio SMS webhooks, using ProjectDiscovery OAST infrastructure to validate callbacks.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.