With the rapid rise of LLMs (Large Language Models) since mid 2024, attacks have rapidly become more frequent and sophisticated targeting vulnerabilities within these models. Cloud-based LLM usage costs can be staggering, surpassing several hundreds of thousands of dollars monthly, making them an attractive target for attackers. The Sysdig TRT since originally discovering LLMjacking in May 2024, has found over a dozen proxy servers using stolen credentials across many different services, including OpenAI, AWS, and Azure. Now, DeepSeek, since it was officially released, has also caught attackers’ attention, with many attackers flocking to the platform to further push the boundaries of LLMjacking.
In this webinar, Sysdig's Threat Research Teams experts Alessandro Brucato and Stefano Chierici discuss the evolution of LLMjacking attacks, including the targeting of DeepSeek. They detail the methods used by attackers, such as the use of OpenAI Reverse Proxies (ORPs), and will also discuss the costs associated with LLMjacking and provide best practices for detecting and combating LLMjacking.