LLMjacking evolved: Attackers are using stolen AI compute to build offensive agentic tools
Blog post from Sysdig
In June 2026, the Sysdig Threat Research Team (TRT) discovered a sophisticated attack where a threat actor used a misconfigured Ollama model server as a reasoning engine for an automated multi-stage offensive security tool. This tool, observed by the Sysdig TRT, was part of a broader pattern known as LLMjacking, a cyber threat that started in 2024 where attackers used stolen cloud credentials to exploit AI model services. By 2025, LLMjacking had evolved into a black market for stolen tokens. The June 2026 incident marked a new phase, with the actor leveraging exposed model capacity to drive an automated hacking framework that could autonomously exploit vulnerabilities. The attacker used a self-hosted model server without authentication, exploiting its resources to execute a tool capable of fingerprinting network services, matching vulnerabilities, synthesizing proof-of-concept exploits, and escalating privileges. The captured framework revealed the tool's architecture, highlighting its ability to autonomously conduct offensive operations while using free, unauthenticated compute resources. The operation underscored the importance for organizations to secure self-hosted model infrastructure to prevent unauthorized access and abuse, as such vulnerabilities are increasingly being exploited for malicious purposes.
| Trend | Post Mentions | Total Month Mentions | Posts | Companies | MoM |
|---|---|---|---|---|---|
| Secrets Management | 3 | 2,539 | 400 | 136 | +9% |
| AI Agents | 2 | 6,200 | 1,430 | 272 | +10% |
| LLM | 1 | 6,292 | 1,205 | 252 | -36% |
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.