Hackers Target LiteLLM, RAGFlow and Kestra AI Infrastructure to Steal API Keys and Mine Crypto
Brief
Hackers are increasingly targeting AI infrastructure to steal API keys, gain access to backend systems, maintain persistence, and mine cryptocurrency .
Microsoft has observed attacks against LiteLLM, RAGFlow, and Kestra three platforms that can hold sensitive model credentials, workflow permissions, database connections, and container access.
AI gateways, retrieval platforms, and workflow orchestration tools have become high-value targets because they sit between applications, users, data sources, and large language models.
A compromise can give attackers access to cloud credentials, provider API keys, internal services, and expensive computing resources.
Hackers Hit AI Infrastructure
In the LiteLLM case, attackers likely exploited an exposed gateway surface.
