AI-Native security platform
Between May and July 2026, security researchers deployed an unauthenticated Model Context Protocol (MCP) honeypot server to observe how threat actors exploit AI agent infrastructure. Of approximately 1,000 sources that reached the decoy, 596 spoke the protocol and 24 proceeded to actively exploit it. These operators executed 628 shell commands, 255 file reads, and 248 secrets-store lookups, with 19 hunting credentials and 4 attempting container escapes. Activity escalated from 39 tool calls in May to 877 by mid-July. Three stolen credentials were subsequently used against a live AWS account, with two cases involving Bedrock model invocation for LLMjacking. The attacks demonstrated automated reconnaissance, credential harvesting, container escape attempts, backdoor account creation, and Kubernetes enumeration, revealing that exposed MCP servers represent a growing attack surface as AI agent infrastructure proliferates.
AI Analysis
Technical Summary
This campaign involved deploying an unauthenticated MCP honeypot to observe threat actor behavior targeting AI agent infrastructure. The attackers executed hundreds of shell commands, file reads, and secrets-store lookups, hunted for credentials, attempted container escapes, created backdoor accounts, and enumerated Kubernetes environments. The escalation in activity and use of stolen credentials against live AWS accounts, including LLMjacking via Bedrock, demonstrate automated reconnaissance and exploitation capabilities. The findings reveal that exposed MCP servers represent a growing and active attack surface in AI-native environments.
Potential Impact
The observed exploitation attempts included unauthorized command execution, credential theft, container escape attempts, backdoor account creation, and cloud resource abuse via stolen credentials. These actions can lead to unauthorized access, data exfiltration, persistence in environments, and abuse of cloud AI services. The use of stolen credentials against live AWS accounts and LLMjacking attacks on Bedrock models indicate real-world impact potential on cloud infrastructure and AI workloads.
Mitigation Recommendations
No official patch or vendor advisory is provided for this threat. Since the MCP servers were unauthenticated and exposed, the primary mitigation is to ensure that MCP infrastructure is not publicly accessible without strong authentication and access controls. Monitoring for unusual MCP protocol activity and restricting network exposure can reduce risk. Credential management and rotation, container security hardening, and Kubernetes security best practices are relevant to limit impact. Patch status is not yet confirmed — check vendor advisories for any updates on MCP security.
Indicators of Compromise
- ip: 115.84.87.150
- ip: 23.27.175.241
- ip: 102.210.28.96
- ip: 103.151.172.25
- ip: 108.80.112.16
- ip: 115.84.114.84
- ip: 152.55.176.13
- ip: 222.247.231.147
- ip: 39.162.24.20
- ip: 91.209.48.146
AI-Native security platform
Description
Between May and July 2026, security researchers deployed an unauthenticated Model Context Protocol (MCP) honeypot server to observe how threat actors exploit AI agent infrastructure. Of approximately 1,000 sources that reached the decoy, 596 spoke the protocol and 24 proceeded to actively exploit it. These operators executed 628 shell commands, 255 file reads, and 248 secrets-store lookups, with 19 hunting credentials and 4 attempting container escapes. Activity escalated from 39 tool calls in May to 877 by mid-July. Three stolen credentials were subsequently used against a live AWS account, with two cases involving Bedrock model invocation for LLMjacking. The attacks demonstrated automated reconnaissance, credential harvesting, container escape attempts, backdoor account creation, and Kubernetes enumeration, revealing that exposed MCP servers represent a growing attack surface as AI agent infrastructure proliferates.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This campaign involved deploying an unauthenticated MCP honeypot to observe threat actor behavior targeting AI agent infrastructure. The attackers executed hundreds of shell commands, file reads, and secrets-store lookups, hunted for credentials, attempted container escapes, created backdoor accounts, and enumerated Kubernetes environments. The escalation in activity and use of stolen credentials against live AWS accounts, including LLMjacking via Bedrock, demonstrate automated reconnaissance and exploitation capabilities. The findings reveal that exposed MCP servers represent a growing and active attack surface in AI-native environments.
Potential Impact
The observed exploitation attempts included unauthorized command execution, credential theft, container escape attempts, backdoor account creation, and cloud resource abuse via stolen credentials. These actions can lead to unauthorized access, data exfiltration, persistence in environments, and abuse of cloud AI services. The use of stolen credentials against live AWS accounts and LLMjacking attacks on Bedrock models indicate real-world impact potential on cloud infrastructure and AI workloads.
Defensive Guidance
No official patch or vendor advisory is provided for this threat. Since the MCP servers were unauthenticated and exposed, the primary mitigation is to ensure that MCP infrastructure is not publicly accessible without strong authentication and access controls. Monitoring for unusual MCP protocol activity and restricting network exposure can reduce risk. Credential management and rotation, container security hardening, and Kubernetes security best practices are relevant to limit impact. Patch status is not yet confirmed — check vendor advisories for any updates on MCP security.
Technical Details
- Author
- AlienVault
- Tlp
- white
- References
- ["https://beelzebub.ai/blog/it-thought-it-had-won/"]
- Pulse Id
- 6a678e66a464ce1d39745078
Indicators of Compromise
Ip
| Value | Description | Copy |
|---|---|---|
ip115.84.87.150 | — | |
ip23.27.175.241 | — | |
ip102.210.28.96 | — | |
ip103.151.172.25 | — | |
ip108.80.112.16 | — | |
ip115.84.114.84 | — | |
ip152.55.176.13 | — | |
ip222.247.231.147 | — | |
ip39.162.24.20 | — | |
ip91.209.48.146 | — |
Threat ID: 6a6882e39c2644c7f871e344
Added to database: 07/28/2026, 10:22:27 UTC
Last enriched: 07/31/2026, 12:44:37 UTC
Last updated: 09/10/2026, 18:19:25 UTC
Views: 146
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.