Threat activity observed in late 2025 and early 2026 shows high-volume, automated probing of emerging and legacy internet-facing attack surfaces, including exposed large language model (LLM) endpoints. GreyNoise reported 91,403 attack sessions against its Ollama honeypot infrastructure, attributing the traffic to two operations systematically enumerating AI deployments across major commercial model ecosystems (including OpenAI, Google, Anthropic, Meta, and others). One operation used two IP addresses to methodically test API formats and identify live endpoints across dozens of LLM targets while relying on innocuous prompts (for example, simple greetings and basic trivia questions) to reduce the likelihood of detection; GreyNoise noted the source IPs had prior associations with exploitation of known vulnerabilities, suggesting reconnaissance intended to feed follow-on exploitation.
In parallel, Check Point Research detailed an updated, modular GoBruteforcer botnet variant that compromises Linux servers by brute-forcing weak credentials across common services (including FTP, MySQL, PostgreSQL, and phpMyAdmin), then reuses newly compromised hosts to expand scanning and password-guessing at scale. Check Point assessed that 50,000+ internet-facing servers may be exposed to this activity, citing two drivers: widespread reuse of AI-generated deployment/configuration examples that propagate predictable usernames and weak defaults, and continued exposure of legacy stacks (such as XAMPP) with insufficient hardening. The newer GoBruteforcer variant reportedly adds more sophisticated capabilities and obfuscation, and the operators appear financially motivated, with activity linked to data theft, selling initial access, and cryptocurrency theft.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
On Jan. 12, 2026, Check Point Research disclosed a more sophisticated GoBruteforcer variant that brute-forces weak credentials on common services and uses compromised Linux servers to scan public IP ranges and attempt further logins. The researchers estimated that more than 50,000 Internet-facing servers may be vulnerable.
From October 2025 through January 2026, GreyNoise recorded 91,403 attack sessions against its Ollama honeypot infrastructure, linking the activity to coordinated reconnaissance intended to map AI deployment attack surfaces and identify misconfigured proxies that could expose commercial AI APIs.
Starting Dec. 28, 2025, two IP addresses launched an 11-day enumeration campaign against more than 73 LLM-related endpoints, probing API formats associated with providers including OpenAI and Google Gemini while using benign prompts like "hi."
Around Dec. 25, 2025, the SSRF-focused operation surged, generating 1,688 sessions in two days from infrastructure spread across multiple countries. GreyNoise observed shared automation characteristics, including a dominant JA4H fingerprint consistent with tooling such as Nuclei.
A campaign targeting exposed LLM infrastructure with server-side request forgery techniques began in October 2025, abusing vectors such as Ollama model-pull registry URL injection and Twilio SMS webhook MediaUrl manipulation to trigger outbound callbacks.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
govinfosecurity.com
Open sourcebankinfosecurity.com
Open sourcedarkreading.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.