Inside 90 days of attacks on AI infrastructure
AI Summary
Wiz Threat Research observed 90 days of sustained attacks against AI infrastructure through honeypots deployed across services like LiteLLM, Flowise, and LangChain. Attackers exploited vulnerabilities in MCP servers, including authentication bypass and command injection (CVE-2026-59822, CVE-2026-42271), to achieve remote code execution and deploy cryptominers. A second pattern involved blind prompt injection against AI agent frameworks, where attackers used out-of-band DNS callbacks to confirm execution and later fetch payloads from Pastebin. Post-exploitation activity was tailored to AI environments, including in-memory extraction of LiteLLM master keys, model enumeration, and use of environment-specific camouflage to hide malicious binaries.
AI-extracted · verify before operational use
Extracted Entities 5 found
Indicators of Compromise 10 extracted
| Type | Value | Detail |
|---|---|---|
| IP | 185[.]62[.]1[.]8 | Details → |
| IP | 185[.]84[.]98[.]85 | Details → |
| IP | 94[.]26[.]106[.]29 | Details → |
| Domain | pool[.]hashvault[.]pro | Details → |
| Domain | crazyeltonproxy[.]top | Details → |
| Domain | 1710[.]rwlp[.]be | Details → |
| Filename | /tmp/.dbus-cache/gmon | Details → |
| Filename | /tmp/.dbus-cache | Details → |
| Filename | /tmp/x86_64 | Details → |
| Filename | /tmp/amd64 | Details → |