Close Menu
    Facebook X (Twitter) Instagram
    Wifi PortalWifi Portal
    • Blogging
    • SEO & Digital Marketing
    • WiFi / Internet & Networking
    • Cybersecurity
    • Tech Tools & Mobile / Apps
    • Privacy & Online Earning
    Facebook X (Twitter) Instagram
    Wifi PortalWifi Portal
    Home»Cybersecurity»LLMs Hijacked, Monetized in ‘Operation Bizarre Bazaar’
    Cybersecurity

    LLMs Hijacked, Monetized in ‘Operation Bizarre Bazaar’

    adminBy adminJanuary 29, 2026No Comments3 Mins Read
    Facebook Twitter LinkedIn Telegram Pinterest Tumblr Reddit WhatsApp Email
    LLMjacking
    Share
    Facebook Twitter LinkedIn Pinterest Email

    As part of a broad LLMjacking operation, cybercriminals are searching for, hijacking, and monetizing exposed LLM and MCP endpoints at scale, Pillar Security reports.

    The campaign, dubbed Operation Bizarre Bazaar, targets exposed or unprotected AI endpoints to hijack system resources, resell API access, exfiltrate data, and move laterally to internal systems.

    The attacks mainly impact self-hosted LLM infrastructure, including endpoints with exposed default ports, unauthenticated APIs, development/staging environments, and MCP servers.

    “The threat differs from traditional API abuse because compromised LLM endpoints can generate significant costs (inference is expensive), expose sensitive organizational data, and provide lateral movement opportunities,” Pillar explains.

    Operation Bizarre Bazaar involves three interconnected entities: a scanner (bot infrastructure that scours the web for exposed systems), a validator (tied to silver.inc, it validates identified endpoints), and a marketplace (The Unified LLM API Gateway, controlled by silver.inc).

    Identified targets are validated by silver.inc through systematic API testing within 2 to 8 hours after the scanning activity. The threat actors were seen enumerating model capabilities and assessing response quality.

    Advertisement. Scroll to continue reading.

    The marketplace, the cybersecurity firm says, offers access to over 30 LLMs. It is hosted on bulletproof infrastructure in the Netherlands, and marketed on Discord and Telegram, with payments made via cryptocurrency or PayPal.

    Pillar has observed over 35,000 attack sessions associated with the operation, at an average of 972 attacks per day.

    “The sustained high-volume activity confirms systematic targeting of exposed AI infrastructure rather than opportunistic scanning,” Pillar notes.

    Exploited systems include Ollama instances on port 11434 without authentication, web-exposed OpenAI-compatible APIs on port 8000, exposed MCP servers with no access control, development environments with public IPs, and production chatbots that lack authentication or rate limits.

    The operation, the company notes, is run by a threat actor using the moniker Hecker, who is also known as Sakuya and LiveGamer101, and appears linked through infrastructure overlaps with the nexeonai.com service.

    “These attackers target the path of least resistance—endpoints with no friction. Even publicly accessible AI services can deter opportunistic abuse through rate limiting, usage caps, and behavioral monitoring. For internal services, the calculus is simpler: if it shouldn’t be public, verify it isn’t—scan your external attack surface regularly,” Pillar notes.

    Separately, the company identified a reconnaissance campaign targeting MCP servers, likely operated by a different threat actor with different objectives.

    “By late January, 60% of total attack traffic came from MCP-focused reconnaissance operations,” Pillar notes.

    Related: LLMs in Attacker Crosshairs, Warns Threat Intel Firm

    Related: Why We Can’t Let AI Take the Wheel of Cyber Defense

    Related: Vibe Coding Tested: AI Agents Nail SQLi but Fail Miserably on Security Controls

    Related: WormGPT 4 and KawaiiGPT: New Dark LLMs Boost Cybercrime Automation

    Bazaar Bizarre Hijacked LLMs Monetized Operation
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email
    Previous ArticleHow Visibility Compounds In Brand-Led SEO
    Next Article Best Buy just quietly carved $100 off a truly iconic Garmin watch – but is the Venu 3 still worth the money?
    admin
    • Website

    Related Posts

    LLMs ‘Would Not Exist’ Without Reddit Data

    May 25, 2026

    Encryption Consulting launches CertSecure Manager v3.3 with zero-touch certificate renewals

    May 20, 2026

    GitHub confirms breach of 3,800 repos via malicious VSCode extension

    May 20, 2026
    Add A Comment
    Leave A Reply Cancel Reply

    Search Blog
    About
    About

    At WifiPortal.tech, we share simple, easy-to-follow guides on cybersecurity, online privacy, and digital opportunities. Our goal is to help everyday users browse safely, protect personal data, and explore smart ways to earn online. Whether you’re new to the digital world or looking to strengthen your online knowledge, our content is here to keep you informed and secure.

    Trending Blogs

    From keyword manager to system optimizer

    June 4, 2026

    11 Ways to Lower Your Cell Phone Bill

    June 3, 2026

    Google Search Console adds AI performance reports and blocking controls

    June 3, 2026

    Cisco sees quantum networking as the future of networking

    June 3, 2026
    Categories
    • Blogging (89)
    • Cybersecurity (1,955)
    • Privacy & Online Earning (233)
    • SEO & Digital Marketing (1,361)
    • Tech Tools & Mobile / Apps (1,796)
    • WiFi / Internet & Networking (329)

    Subscribe to Updates

    Stay updated with the latest tips on cybersecurity, online privacy, and digital opportunities straight to your inbox.

    WifiPortal.tech is a blogging platform focused on cybersecurity, online privacy, and digital opportunities. We share easy-to-follow guides, tips, and resources to help you stay safe online and explore new ways of working in the digital world.

    Our Picks

    From keyword manager to system optimizer

    June 4, 2026

    11 Ways to Lower Your Cell Phone Bill

    June 3, 2026

    Google Search Console adds AI performance reports and blocking controls

    June 3, 2026
    Most Popular
    • From keyword manager to system optimizer
    • 11 Ways to Lower Your Cell Phone Bill
    • Google Search Console adds AI performance reports and blocking controls
    • Cisco sees quantum networking as the future of networking
    • How To Use Lighthouse To Test Your Website For Agentic Readiness
    • Landing Page Copywriting: How to Write Copy That Converts
    • Shopify outage disrupts stores, checkouts and admin access
    • Google adds a dedicated Agentic Browsing category to Lighthouse
    © 2026 WifiPortal.tech. Designed by WifiPortal.tech.
    • Home
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms and Conditions
    • Disclaimer

    Type above and press Enter to search. Press Esc to cancel.