News Room
16
Share
Threat Actors Pose as OpenAI, Anthropic and Google AI Crawlers to Harvest .env Files, AWS Keys and Private Certificates
mediumThreat Intelligence

Threat Actors Pose as OpenAI, Anthropic and Google AI Crawlers to Harvest .env Files, AWS Keys and Private Certificates

GreyNoise reports scanners spoofing the user-agents of OpenAI, Anthropic, DeepSeek, Google and Perplexity crawlers to request .env files, AWS credentials and private keys from misconfigured hosts — traffic that ignores robots.txt and originates outside published crawler ranges.

02 September 2026Last updated 02 September 20264 min readGreyNoise
E
Encrygma AI Cyber Weapons Advisory Services :We provide AI Cyber Warfare Technologies Reports, including full technical blueprints, tech source codes, entire know how. Consult with us. Click Here

Executive Takeaway — TL;DR

Category:
Threat Intelligence
Severity:
Medium
Actor Type:
Cybercriminal
Geography:
Global
Confidence:
Confirmed
MITRE ID:
T1595.002, T1552.001
Source:
GreyNoise
Read Time:
4 min

Borrowed Trust, Stolen Secrets

GreyNoise published research on 28 August 2026 — syndicated widely through 1 September — documenting a sustained scanning campaign in which threat actors spoof the user-agent strings of legitimate AI crawlers: OpenAI's GPTBot, Anthropic's ClaudeBot, DeepSeek, Google's AI crawlers, Perplexity and related agents.

The disguise buys the scanners tolerance from operators who have allow-listed AI crawlers, while the requests themselves target .env files, AWS credential files, private keys, configuration backups and other secrets frequently left exposed on misconfigured web hosts.

How to Tell Real Crawlers From Forgeries

GreyNoise's telemetry makes the distinction clear:

  • The traffic does not originate from the published IP ranges of any legitimate AI crawler.
  • It largely ignores robots.txt, which genuine crawlers honor.
  • Request patterns focus on secret-bearing paths rather than indexable content.

This is classic brand-trust abuse for credential reconnaissance — not a compromise of any AI system — but the scale of allow-listing for AI crawlers gives the technique unusually broad reach.

Defensive Implications

  • Verify AI-crawler traffic against vendor-published IP ranges; never trust user-agent alone.
  • Block or alert on requests for .env, .aws/credentials, .pem, .git/ and similar paths from any source.
  • Audit web roots for accidentally deployed secret files and rotate anything found.
  • Feed forged-crawler indicators into WAF and honeypot rules — the traffic is high-volume and easy to fingerprint.

Sources

GreyNoise, "Threat actors posing as AI crawlers" (28 Aug 2026); amplified by Cyber Security News and Help Net Security.

Professional Spy Phones — ZERO-CLICK Spyware: Samsung Galaxy and iPhone hardware-modified with a dedicated implant for remote surveillance, lawful interception, and corporate compliance monitoring.
ENCRYGMA

Need Zero Click Spyware for Android and iOS?

Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.

Request a demo