
Threat Actors Pose as OpenAI, Anthropic and Google AI Crawlers to Harvest .env Files, AWS Keys and Private Certificates
GreyNoise reports scanners spoofing the user-agents of OpenAI, Anthropic, DeepSeek, Google and Perplexity crawlers to request .env files, AWS credentials and private keys from misconfigured hosts — traffic that ignores robots.txt and originates outside published crawler ranges.
Executive Takeaway — TL;DR
- Category:
- Threat Intelligence
- Severity:
- Medium
- Actor Type:
- Cybercriminal
- Geography:
- Global
- Confidence:
- Confirmed
- MITRE ID:
- T1595.002, T1552.001
- Source:
- GreyNoise
- Read Time:
- 4 min
Borrowed Trust, Stolen Secrets
GreyNoise published research on 28 August 2026 — syndicated widely through 1 September — documenting a sustained scanning campaign in which threat actors spoof the user-agent strings of legitimate AI crawlers: OpenAI's GPTBot, Anthropic's ClaudeBot, DeepSeek, Google's AI crawlers, Perplexity and related agents.
The disguise buys the scanners tolerance from operators who have allow-listed AI crawlers, while the requests themselves target .env files, AWS credential files, private keys, configuration backups and other secrets frequently left exposed on misconfigured web hosts.
How to Tell Real Crawlers From Forgeries
GreyNoise's telemetry makes the distinction clear:
- The traffic does not originate from the published IP ranges of any legitimate AI crawler.
- It largely ignores robots.txt, which genuine crawlers honor.
- Request patterns focus on secret-bearing paths rather than indexable content.
This is classic brand-trust abuse for credential reconnaissance — not a compromise of any AI system — but the scale of allow-listing for AI crawlers gives the technique unusually broad reach.
Defensive Implications
- Verify AI-crawler traffic against vendor-published IP ranges; never trust user-agent alone.
- Block or alert on requests for
.env,.aws/credentials,.pem,.git/and similar paths from any source. - Audit web roots for accidentally deployed secret files and rotate anything found.
- Feed forged-crawler indicators into WAF and honeypot rules — the traffic is high-volume and easy to fingerprint.
Sources
GreyNoise, "Threat actors posing as AI crawlers" (28 Aug 2026); amplified by Cyber Security News and Help Net Security.
Sources
- 1.GreyNoise — Threat actors posing as AI crawlersPrimary telemetry research
- 2.Cyber Security News — Hackers pose as OpenAI, Anthropic to steal secretsSyndicated coverage
Need Zero Click Spyware for Android and iOS?
Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.
Related Intelligence

Qilin and TheGentlemen Lead Global Ransomware Surge Targeting Critical Infrastructure and Professional Services

Krybit Ransomware Syndicate Escalates Global Campaign Targeting Critical Infrastructure and Legal Entities

