Campaign comparison
One Operator, Every LLM Key They Could Reach vs Polydrop: Dissecting a Four-Stage Implant Chain Delivered via Langflow RCE
2026-10-02 · 2026-06-03
Link signals
No overlapping infrastructure, tooling, techniques, or CVEs. These two campaigns are independent on every comparable axis.
Actor & objective
Actor
unattributed
vs
unattributed
different
Objective
LLM/cloud credential theft for free AI compute access
vs
data-exfiltration
different
Kill chain
= same stage & technique ≠ same stage, different technique • unique to one campaign
One Operator, Every LLM Key They Could Reach
-
unique step: 1. credential-access
· T1552.001
Jenkins Script Console Groovy enumerates AWS/ANTHROPIC/SECRET env vars, reads credentials.xml
-
unique step: 2. credential-access
· T1552.001
Docker API container inspection finds a planted AWS key in a container environment block
-
unique step: 3. privilege-escalation
· T1078.004
PutUserPolicy self-grant attempt against the stolen key after Bedrock InvokeModel is denied
-
unique step: 4. impact
· T1496
RunInstances and repeated InvokeModel attempts against the stolen key, all denied (zero-permission decoy)
-
unique step: 5. credential-access
· T1552.001
Multi-provider API key sweep (Anthropic/OpenAI/OpenRouter prefixes) via Docker exec and Langflow code execution, a week later
Polydrop: Dissecting a Four-Stage Implant Chain Delivered via Langflow RCE
-
unique step: 1. initial-access
· T1190
unauth RCE via Langflow code-eval endpoint
-
unique step: 2. execution
· T1059.006
python one-liner stages the Go loader
-
unique step: 3. defense-evasion
· T1027
garble-obfuscated symbols, GoReSym-resistant
-
unique step: 4. persistence
· T1543
multi-init systemd + cron + shell rc
-
unique step: 5. exfiltration
· T1041
Alibaba OSS SDK upload over TLS
Side by side
green = shared by both campaigns.
| One Operator, Every LLM Key They Could Reach | Polydrop: Dissecting a Four-Stage Implant Chain Delivered via Langflow RCE |
|---|---|
| Procedures | |
| docker-api-exec:container-env-inspect+key-exfiljenkins-groovy-console:env-enum+credential-file-readprovider-key-sweep:multi-prefix-grep-env-and-filesystemstolen-key-decision-tree:identity-check-then-model-invoke-then-self-grant-then-retry | arch-sweep:uname-m->arch-tagged-urlfileless:memfd+fexecvehistory-suppression:HISTFILEruntime-tasking:no-targeting-in-binary |
| Toolmarks | |
| — | buildenv:/home/vbccsbpacker:garble-no-literals |
| C2 protocol | |
| — | tcp+single-byte-xor; url-grammar ?h=&p=&t=tcp&a={l64|l32|a64|a32}&stage=true |
| Tooling | |
| — | alibaba-oss-sdkgarblememfd-loader |
| Capabilities | |
| cloud-api-abusecredential-harvestingllm-credential-theft | fileless-loadermemfd-execmulti-init-persistencesocks5-tunnel |
| C2 | |
| — | 149.104.29.201 |
| ASNs | |
| AS41745 | AS139659 |
| CVEs | |
| — | CVE-2025-3248 |
| Products | |
| shared: LangflowDocker APIJenkins | shared: Langflow |
| Sectors | |
| — | ai-ml-tooling |
| Geographies | |
| shared: global | shared: global |