The proxy case
An attacker compromised more than 87,000 IP addresses by brute-forcing devices running PPTP and L2TP, two legacy VPN protocols still alive in many networks.
The credentials he tried were the "admin123" type, the factory default username and password almost nobody changes.
With those IPs rented out as proxies he pulled in 202,000 dollars since 2024, according to the case report (Source: escudodigital.com, cybernews).
He automated the whole operation with a modified version of Claude Code, Anthropic's command-line interface for coding with a model.
In other words, he took a tool meant to help a developer write code faster and turned it into the engine of a proxy business.
A single operator holding what used to require a team working shifts.
The pattern
The week brings more pieces of the same kind.
Mandiant published its AI Risk and Resilience 2026 report and describes the jump from experimenting with AI to using it in real operations, with prompt injection as the main vector in self-hosted deployments (Source: cloud.google.com).
Unit 42 and Mandiant push the same idea and add a number that orders everything else: 65% of initial access already arrives through identity, and the cycle closes in minutes (Source: unit42.paloaltonetworks.com).
The common shape is this, the attacker does not break cryptography or hunt for an exotic flaw because he walks in with a credential that already existed and automates the rest.
In the proxy case the credential was "admin123". In the others it is usually a token, a session or a service account.
Shadow AI and the lack of inventory are the dominant gaps Mandiant points to, and they fit everything above.
The other side
The same week shows the inverse move, the agent as the attacker's tool and as the target of the attack.
Hacktron used Claude Opus 5 to build a working exploit, a heap overflow in libheif, and chained it with an SSO flaw in OpenAI's forum until it reached employee accounts and internal repositories, with 6,500 dollars in bounty (Source: securityweek.com).
Remember? I talked about this in the previous post.
Anthropic reported illicit distillation campaigns against Claude from seven labs in China, and Alibaba's reached almost 3 million exchanges per day from 3,500 fraudulent accounts (Source: anthropic.com).
Distilling is training your own model on another's answers... this has been known for a while... you do not touch the provider's infrastructure, you extract its capability through the API door.
This makes me think the barrier to entry is no longer technical but one of permissions or subscriptions, and whoever holds a valid account holds the engine.
The consequence is that this ends in KYC.
What will make you scratch your head is, if they supposedly have our data, why is this reported as something bad but they do not cut the API to the distillers?
The vendor's answer
OpenAI classified GPT-6 Astra as "Critical" level in cybersecurity, with 100% on ExploitBench and the ability to find and develop zero-days, and it already blocks proof-of-concept requests (Source: thehackernews.com, openai.com).
Microsoft opened public comments on a code of conduct for its future models, with three requirements:
1) Accept human correction and shutdown
2) Explain its decisions
3) Deny any legal personhood
(Source: marketingprofs.com)
Newsom signed an executive order to speed up independent oversight and study a mandatory kill switch on frontier models, moving the state registry of auditors from December 2028 to December 2027 (Source: politico.com, gov.ca.gov).
And in the courts, four paying subscribers are suing Anthropic, OpenAI, Google DeepMind and SpaceXAI for allegedly coordinating a slowdown in AI development, leaning on Amodei's September 12 essay and the public backing from Altman, Musk and Hassabis that same day (Source: cnn.com, opb.org, abcnews.com).
My reading is that the vendor is trying to put up doors while the regulator argues about where the hinges go.
Oh, I forgot another of my conclusions... they are taking us for a ride.
What to look at
Audit your VPNs. Look for PPTP and L2TP in the inventory and shut down whatever has no owner.
Trim identity permissions. If 65% of initial access arrives through identity, the question is not which patch is missing but which account can reach production on its own.
Separate the agent from the data. An agent with access to the API and to the internal network is both things at once, or use your own infrastructure.
How I would test it in my lab
I would spin up a container with a legacy VPN service on purpose and run a default-credential scan against it without leaving my network.
I want to see what it leaves in the log and how long it takes for the first useful trace to show up.
Then I would repeat the test with a small local agent generating the combinations to measure whether the pace changes and whether the log tells it apart from a normal scan.
If the log does not separate the two, the conclusion is that my detection depends on luck and not on a rule, and that honestly makes me uneasy.
Closing
This week's attacker was not a team, it was one person with a modified CLI and a list of default passwords.
What decides whether this touches you is not the sophistication of the attack, it is how many doors in your network are still open with the factory key.
Originally published at https://sammideblas.com/notas/one-attacker-rented-87-000-ips-with-a-modified-ai-cli
Top comments (0)