www.team-cymru.com Massive Network of AI Proxy Servers Used for Malicious Activities Uncovered
Article Content
- •Over 10,000 AI proxy servers identified in China facilitating malicious activities.
- •Proxies are used for bypassing region restrictions and conducting model distillation attacks.
- •Tools like Claude Relay Service and sub2api are integral to this malicious ecosystem.
Security researchers from Team Cymru have identified over 10,000 proxy servers in China facilitating malicious AI activities. These servers, termed 'transfer stations,' are primarily used to bypass geographic restrictions and conduct model distillation attacks against frontier AI models. The infrastructure allows actors to obscure their identities while accessing and abusing AI services, including credential sharing and resale. Tools like Claude Relay Service and sub2api have been linked to this ecosystem, which is designed to violate terms of service of AI providers. The findings highlight a significant risk to intellectual property and compliance for AI model providers. Current exploitation status indicates active use of these proxies for malicious purposes. This situation raises concerns about the integrity of AI systems and the potential for widespread abuse.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Continue Reading
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…
Critical Linux Kernel Vulnerability CVE-2025-39682 Under Active Exploitation A critical vulnerability (CVE-2025-39682) in the Linux kernel allows remote code execution through mishandling of zero-length TLS records. This flaw affects kTLS-enabled hosts running vulnerable kernel versions, exposing them to attackers without authentication. CISA added this vulnerability to its Known Exploited…