SSRF Campaign — Campaign Analysis & Threat Activity

Threat entity extracted from intelligence sources

Frequency
1
occurrences
First Seen
January 8, 2026
Last Seen
January 8, 2026

SSRF Campaign is a threat campaign tracked across 1 threat cluster and 1 intelligence report mention on ThreatCluster. First observed January 8, 2026; most recent activity January 8, 2026.

Overview

SSRF Campaign denotes a threat operation that exploits server-side request forgery vulnerabilities to target large language model (LLM) deployments, enabling attackers to access internal resources and potentially exfiltrate data or pivot within cloud environments. Its significance lies in highlighting how misconfigured or exposed LLM infrastructure can be hijacked through SSRF to bypass perimeter controls and compromise confidential information.

Related Threat Clusters

  • Hackers Exploit Misconfigured Proxies to Access LLM Services

    Threat actors have been targeting misconfigured proxy servers to gain unauthorized access to commercial large language model (LLM) services. This campaign, which began in late December 2025, has seen over 91,000 attack…

    4 articles · Updated January 9, 2026

Recent Intelligence Reports

  • Threat Actors Actively Targeting LLMs — Greynoise · January 8, 2026

CVSS v3.1 Breakdown