Campaign comparison

One Operator, Every LLM Key They Could Reach vs Polydrop: Dissecting a Four-Stage Implant Chain Delivered via Langflow RCE

2026-10-02  ·  2026-06-03

Link signals

No overlapping infrastructure, tooling, techniques, or CVEs. These two campaigns are independent on every comparable axis.

Actor & objective

Actor unattributed vs unattributed different
Objective LLM/cloud credential theft for free AI compute access vs data-exfiltration different

Kill chain

= same stage & technique   ≠ same stage, different technique   • unique to one campaign

One Operator, Every LLM Key They Could Reach

  1. unique step: 1. credential-access · T1552.001
    Jenkins Script Console Groovy enumerates AWS/ANTHROPIC/SECRET env vars, reads credentials.xml
  2. unique step: 2. credential-access · T1552.001
    Docker API container inspection finds a planted AWS key in a container environment block
  3. unique step: 3. privilege-escalation · T1078.004
    PutUserPolicy self-grant attempt against the stolen key after Bedrock InvokeModel is denied
  4. unique step: 4. impact · T1496
    RunInstances and repeated InvokeModel attempts against the stolen key, all denied (zero-permission decoy)
  5. unique step: 5. credential-access · T1552.001
    Multi-provider API key sweep (Anthropic/OpenAI/OpenRouter prefixes) via Docker exec and Langflow code execution, a week later

Polydrop: Dissecting a Four-Stage Implant Chain Delivered via Langflow RCE

  1. unique step: 1. initial-access · T1190
    unauth RCE via Langflow code-eval endpoint
  2. unique step: 2. execution · T1059.006
    python one-liner stages the Go loader
  3. unique step: 3. defense-evasion · T1027
    garble-obfuscated symbols, GoReSym-resistant
  4. unique step: 4. persistence · T1543
    multi-init systemd + cron + shell rc
  5. unique step: 5. exfiltration · T1041
    Alibaba OSS SDK upload over TLS

Side by side

green = shared by both campaigns.

Attribute-by-attribute comparison of One Operator, Every LLM Key They Could Reach and Polydrop: Dissecting a Four-Stage Implant Chain Delivered via Langflow RCE. Values labelled "shared" appear in both campaigns.
One Operator, Every LLM Key They Could Reach Polydrop: Dissecting a Four-Stage Implant Chain Delivered via Langflow RCE
Procedures
docker-api-exec:container-env-inspect+key-exfiljenkins-groovy-console:env-enum+credential-file-readprovider-key-sweep:multi-prefix-grep-env-and-filesystemstolen-key-decision-tree:identity-check-then-model-invoke-then-self-grant-then-retryarch-sweep:uname-m->arch-tagged-urlfileless:memfd+fexecvehistory-suppression:HISTFILEruntime-tasking:no-targeting-in-binary
Toolmarks
—buildenv:/home/vbccsbpacker:garble-no-literals
C2 protocol
—tcp+single-byte-xor; url-grammar ?h=&p=&t=tcp&a={l64|l32|a64|a32}&stage=true
Tooling
—alibaba-oss-sdkgarblememfd-loader
Capabilities
cloud-api-abusecredential-harvestingllm-credential-theftfileless-loadermemfd-execmulti-init-persistencesocks5-tunnel
C2
—149.104.29.201
ASNs
AS41745AS139659
CVEs
—CVE-2025-3248
Products
shared: LangflowDocker APIJenkinsshared: Langflow
Sectors
—ai-ml-tooling
Geographies
shared: globalshared: global

← Compare a different pair