AI-Native security platform
Between May and July 2026, security researchers deployed an unauthenticated Model Context Protocol (MCP) honeypot server to observe how threat actors exploit AI agent infrastructure. Of approximately 1,000 sources that reached the decoy, 596 spoke the protocol and 24 proceeded to actively exploit it. These operators executed 628 shell commands, 255 file reads, and 248 secrets-store lookups, with 19 hunting credentials and 4 attempting container escapes. Activity escalated from 39 tool calls in May to 877 by mid-July. Three stolen credentials were subsequently used against a live AWS account, with two cases involving Bedrock model invocation for LLMjacking. The attacks demonstrated automated reconnaissance, credential harvesting, container escape attempts, backdoor account creation, and Kubernetes enumeration, revealing that exposed MCP servers represent a growing attack surface as AI agent infrastructure proliferates.
Indicators of Compromise
- ip: 115.84.87.150
- ip: 23.27.175.241
- ip: 102.210.28.96
- ip: 103.151.172.25
- ip: 108.80.112.16
- ip: 115.84.114.84
- ip: 152.55.176.13
- ip: 222.247.231.147
- ip: 39.162.24.20
- ip: 91.209.48.146
AI-Native security platform
Description
Between May and July 2026, security researchers deployed an unauthenticated Model Context Protocol (MCP) honeypot server to observe how threat actors exploit AI agent infrastructure. Of approximately 1,000 sources that reached the decoy, 596 spoke the protocol and 24 proceeded to actively exploit it. These operators executed 628 shell commands, 255 file reads, and 248 secrets-store lookups, with 19 hunting credentials and 4 attempting container escapes. Activity escalated from 39 tool calls in May to 877 by mid-July. Three stolen credentials were subsequently used against a live AWS account, with two cases involving Bedrock model invocation for LLMjacking. The attacks demonstrated automated reconnaissance, credential harvesting, container escape attempts, backdoor account creation, and Kubernetes enumeration, revealing that exposed MCP servers represent a growing attack surface as AI agent infrastructure proliferates.
Technical Details
- Author
- AlienVault
- Tlp
- white
- References
- ["https://beelzebub.ai/blog/it-thought-it-had-won/"]
- Adversary
- null
- Pulse Id
- 6a678e66a464ce1d39745078
- Threat Score
- null
Indicators of Compromise
Ip
| Value | Description | Copy |
|---|---|---|
ip115.84.87.150 | — | |
ip23.27.175.241 | — | |
ip102.210.28.96 | — | |
ip103.151.172.25 | — | |
ip108.80.112.16 | — | |
ip115.84.114.84 | — | |
ip152.55.176.13 | — | |
ip222.247.231.147 | — | |
ip39.162.24.20 | — | |
ip91.209.48.146 | — |
Threat ID: 6a6882e39c2644c7f871e344
Added to database: 07/28/2026, 10:22:27 UTC
Last updated: 07/28/2026, 21:22:45 UTC
Views: 10
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.