Chinese threat actor pivots infrastructure and leaks 775 API-key IDs from an AI reseller
cyb3rops · x · 2026-07-29
- A Chinese threat actor linked to the Hermes + CyberStrikeAI + SliverC2 cluster appears to have migrated to new infrastructure around 19 Jun 2026.
- The operation also targeted an AI-API reseller selling Claude/GPT access, where an exposed endpoint leaked 775 upstream API-key IDs plus their ban/rate-limit status and full traffic data before being patched.
- The report lists fresh IOCs, including a new primary host, redirector, WireGuard/SOCKS5 exit node, operator IP, and domains tied to a public CVE-intelligence dashboard and a second service.
- The pictured material shows a real-time vulnerability-intelligence site and a chat/report excerpt describing how the /metrics exposure enabled a broader business and operations analysis.
- Attribution clues include an SSH-key artifact pointing to a username and desktop hostname, suggesting the case has moved beyond theory into active incident response.
More from Infra
- Google posts first quarter of negative free cash flow after years of growth — michalmalewicz · 2026-07-29
- South Korea’s AI-linked stocks sink 10.84% as Samsung and SK Hynix plunge — emmanuelvivier · 2026-07-29
- OpenAI launches Presence for real-time voice agents and enterprise chatbots — emmanuelvivier · 2026-07-29
- French Startup ZML Releases Free Inference Server Compatible Across AI Chips — emmanuelvivier · 2026-07-29
- AI Chip Startup SambaNova Raises $1B at $11B Valuation — emmanuelvivier · 2026-07-29
- Microsoft is building internal AI models to cut OpenAI dependence and costs by up to 89% — emmanuelvivier · 2026-07-29