How AI is applied across API Evangelist and APIs.io. Read my AI disclosure →
API Evangelist API Evangelist
Discovery
Learnings
Guidance
Toolbox
Alignment
API Evangelist LLC

LLMjacking evolved: Attackers are using stolen AI compute to build offensive agentic tools

calendar_today June 17, 2026 person Michael Clark, Director of Threat Research domain sysdig

On June 12, 2026, the Sysdig Threat Research Team (TRT) observed a threat actor using a misconfigured Ollama model server as the reasoning engine for an automated, multi-stage offensive security tool. The post shows how LLMjacking has evolved from stealing AI compute for resale into using that stolen compute to power agentic attack tooling.

open_in_new Read original post