← All campaigns

Procedure

docker-api-exec:container-env-inspect+key-exfil

1 campaign

One profiled campaign here — comparison opens up once a second one shares this procedure.

One Operator, Every LLM Key They Could Reach

For three months, one attacker chased a single goal — free AI compute, taken from the machines they broke into. Wherever they landed, they went after two things: cloud login keys they could point at a provider's hosted AI models, and the raw API keys that developers leave sitting in configuration files.

2026-10-02