Skip to content
Massive Network of AI Proxy Servers Used for Malicious Activities Uncovered

Massive Network of AI Proxy Servers Used for Malicious Activities Uncovered

First seen 23 Sep 2026, 07:27 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 23, 2026 at 07:28 UTC
  • Over 10,000 AI proxy servers identified in China facilitating malicious activities.
  • Proxies are used for bypassing region restrictions and conducting model distillation attacks.
  • Tools like Claude Relay Service and sub2api are integral to this malicious ecosystem.

Security researchers from Team Cymru have identified over 10,000 proxy servers in China facilitating malicious AI activities. These servers, termed 'transfer stations,' are primarily used to bypass geographic restrictions and conduct model distillation attacks against frontier AI models. The infrastructure allows actors to obscure their identities while accessing and abusing AI services, including credential sharing and resale. Tools like Claude Relay Service and sub2api have been linked to this ecosystem, which is designed to violate terms of service of AI providers. The findings highlight a significant risk to intellectual property and compliance for AI model providers. Current exploitation status indicates active use of these proxies for malicious purposes. This situation raises concerns about the integrity of AI systems and the potential for widespread abuse.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-09-07
CVE-2026-86296 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-20
CVE-2026-93958 published
A proof-of-concept for a critical vulnerability was released, heightening security risks.
Team Cymru
2026-09-22
CVE-2026-93952 published
A vulnerability was disclosed that is actively being exploited, impacting AI systems.
Team Cymru
2026-09-22
CVE-2026-94127 published
Another vulnerability was disclosed and added to the CISA KEV list for active exploitation.
Team Cymru
2026-09-22
CVE-2026-93616 published
A new vulnerability was published and confirmed to be actively exploited in the wild.
Team Cymru
2026-09-22
CVE-2026-85102 added to CISA KEV
This vulnerability was added to the CISA KEV catalog, indicating active exploitation.
Team Cymru
2026-09-23
CVE-2026-93616 first public PoC
The first public proof-of-concept for this vulnerability was released, increasing urgency for mitigation.
Team Cymru

More articles in this cluster (2)