Security telemetry indicates coordinated, large-scale probing of exposed LLM endpoints consistent with pre-exploitation reconnaissance. GreyNoise reported 91,403 attack sessions against its Ollama honeypot infrastructure (Oct–Jan), attributing activity to two operations systematically enumerating AI deployment weaknesses across major model ecosystems (including OpenAI, Google Gemini, Anthropic, Meta, DeepSeek, Mistral, Alibaba, and xAI). One operation used two IPs to methodically test API formats and identify live endpoints over an 11‑day period, relying on low-noise prompts (e.g., “hi” and simple factual questions) to reduce detection; GreyNoise noted the IPs’ prior association with exploitation of known vulnerabilities, suggesting reconnaissance feeding a broader exploitation pipeline.
In parallel, Check Point described an active GoBruteforcer (GoBrut) botnet wave targeting cryptocurrency and blockchain project databases by brute-forcing services such as FTP, MySQL, PostgreSQL, and phpMyAdmin on Linux, with campaigns amplified by reused AI-generated deployment examples that propagate common usernames and weak defaults, plus exposure from legacy stacks like XAMPP. The Register’s coverage of the WEF Global Cybersecurity Outlook 2026 aligns with these observations at a strategic level, reporting that leaders increasingly prioritize AI security risk assessment and cite data leakage and adversary capability gains as top concerns; however, broader policy and CIO “challenges” commentary does not materially add to the specific reconnaissance/botnet activity described in the threat reporting.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
Check Point disclosed a new wave of GoBruteforcer activity targeting cryptocurrency and blockchain project infrastructure by exploiting weak or default credentials on Linux servers, especially in legacy XAMPP-based environments. The campaign uses exposed FTP to upload a PHP web shell, deploys an updated IRC bot, and in at least one case staged a module to enumerate TRON addresses and query balances.
The World Economic Forum released its Global Cybersecurity Outlook 2026, reporting that 64% of organizations now assess AI tools for security risk before deployment, up from 37% the prior year, and identifying AI as the leading driver of cybersecurity change in 2026.
From late December 2025, GreyNoise saw high-volume enumeration of exposed LLM-related endpoints associated with multiple major AI providers, including activity from IPs 45.88.186[.]70 and 204.76.203[.]125.
GreyNoise observed systematic scanning activity targeting misconfigured proxy servers that could expose access to commercial LLM services, including SSRF attempts involving Ollama model pulls and Twilio SMS webhooks.
Check Point reported seeing a more sophisticated, obfuscated Golang variant of GoBruteforcer in the middle of 2025, indicating the botnet had evolved beyond earlier documented versions.
Palo Alto Networks Unit 42 first documented the GoBruteforcer (GoBrut) malware family, establishing its use as a botnet that compromises Linux systems and brute-forces services such as FTP and databases.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcego.theregister.com
Open sourcethehackernews.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.