
One attacker rented 87,000 IPs with a modified AI CLI
An attacker brute-forced devices running the legacy PPTP and L2TP protocols, hijacked more than 87,000 IP addresses, rented them as proxies for 202,000 dollars since 2024 and automated it with a modified Claude Code.
An attacker compromised more than 87,000 IP addresses by brute-forcing devices that run PPTP and L2TP, two legacy VPN protocols still alive in many networks. The credentials he tried were of the “admin123” type: factory default usernames and passwords that almost nobody changes.
The proxy business
According to the case report, he rented those addresses out as proxies and pulled in 202,000 dollars since 2024. The operation was automated with a modified version of Claude Code, Anthropic’s command-line interface for coding with a model. A tool meant to help a developer write code faster became the engine of a proxy business: one operator doing what used to require a team working shifts.
Identity is the way in
Mandiant’s AI Risk and Resilience 2026 report describes the shift from experimenting with AI to using it in real operations, with prompt injection as the main vector in self-hosted deployments. Unit 42 adds the number that orders the rest: 65% of initial access already arrives through identity, and the cycle closes in minutes. The attacker does not break cryptography or hunt an exotic flaw; he walks in with a credential that already existed and automates the rest. In the proxy case it was “admin123”; elsewhere it is usually a token, a session or a service account. Shadow AI and the lack of an inventory are the gaps Mandiant points to.
Both sides of the same agent
The same week showed the inverse move. Hacktron used Claude Opus 5 to build a working exploit — a heap overflow in libheif — and chained it with an SSO flaw in OpenAI’s forum until it reached employee accounts and internal repositories, with 6,500 dollars in bounty. Anthropic reported illicit distillation campaigns against Claude from seven labs in China; Alibaba’s reached almost 3 million exchanges per day from 3,500 fraudulent accounts. The barrier to entry is no longer technical: whoever holds a valid account holds the engine.
What to do
Audit the VPNs: find PPTP and L2TP in the inventory and shut down whatever has no owner. Trim identity permissions — if most initial access arrives through identity, the question is not which patch is missing but which account can reach production on its own. And separate the agent from the data: an agent with access to the API and to the internal network is both things at once.
SiTech — AI-powered web development
We build fast, modern websites and bring AI into real business workflows. Have a project or a question? We'd love to help.