AI Service Proxies
AI service proxies are like middleman services that let people access powerful AI tools through a shared gateway. While these are often used for legitimate business, bad actors use them to hide their identity and scale up malicious activities, such as stealing information or creating convincing phishing scams, by making their traffic look like it is coming from many different, harmless sources.
AI service proxies are commercial intermediaries that aggregate and resell access to frontier model APIs. Adversaries leverage these services to obfuscate their origin and bypass rate limits or security filters. By distributing malicious requests—such as those for model distillation, command generation, or social engineering—across a diverse pool of accounts and cloud infrastructure, attackers make it significantly harder for security teams to detect and block their operations.
AI service proxies are infrastructure-as-a-service intermediaries that facilitate the unauthorized or anonymized consumption of frontier model APIs. Adversaries utilize these proxies to conduct large-scale, distributed campaigns, including AML.T0024 (Exfiltration via AI Inference API), AML.T0102 (Generate Malicious Commands), and AML.T0052.000 (Spearphishing via Social Engineering LLM). By multiplexing traffic across heterogeneous cloud environments and compromised accounts—often obtained via LLM Jacking—these proxies provide a mechanism for traffic obfuscation, effectively evading behavioral analytics and IP-based reputation filtering employed by model providers.