SSRF Campaign is a threat campaign tracked across 1 threat cluster and 1 intelligence report mention on ThreatCluster. First observed January 8, 2026; most recent activity January 8, 2026.
SSRF Campaign denotes a threat operation that exploits server-side request forgery vulnerabilities to target large language model (LLM) deployments, enabling attackers to access internal resources and potentially exfiltrate data or pivot within cloud environments. Its significance lies in highlighting how misconfigured or exposed LLM infrastructure can be hijacked through SSRF to bypass perimeter controls and compromise confidential information.
Threat actors have been targeting misconfigured proxy servers to gain unauthorized access to commercial large language model (LLM) services. This campaign, which began in late December 2025, has seen over 91,000 attack…