Skip to content
Threat Feed
medium advisory

Anomalous DNS Queries to AI Service Providers

This detection targets anomalous DNS activity where endpoints initiate connections to external AI service providers like Hugging Face or OpenAI, which may indicate data exfiltration or the use of AI APIs for command-and-control communication.

Monitoring DNS requests originating from endpoints to known AI service providers is critical for identifying potential unauthorized data exfiltration or the misuse of generative AI infrastructure for command-and-control (C2) purposes. Recent intelligence, including the SesameOp campaign, has highlighted how attackers leverage services like the OpenAI Assistants API to establish covert communication channels. Unauthorized access to platforms such as Hugging Face and OpenAI may also indicate the inadvertent or intentional transfer of proprietary or sensitive internal data to external models. This analytic focuses on identifying non-standard processes attempting to resolve domain names associated with popular AI platforms, allowing security teams to enforce data governance and maintain visibility into suspicious outbound traffic patterns.

Impact

Successful exploitation of these patterns can lead to the exfiltration of intellectual property, the bypass of internal data loss prevention controls, and the establishment of persistent, difficult-to-detect C2 infrastructure leveraging legitimate cloud-based AI services. Organizations failing to monitor these outbound flows risk losing control over sensitive internal information processed by external model providers.

Recommendation

  • Enable Sysmon Event ID 22 (DNS Query) logging across all endpoints to capture the required telemetry.
  • Implement the provided detection logic to flag unexpected processes communicating with api.openai.com or router.huggingface.co.
  • Maintain an allowlist of authorized applications and services permitted to communicate with AI model APIs to reduce false positives from research or development teams.
  • Investigate any alerts identifying non-standard processes, especially those lacking digital signatures, initiating connections to these domains.

Immediate actions

Enable Sysmon DNS logging and monitor traffic to the specified domains.

SOC 24h

Threat Hunt

Search for DNS queries to ai platform domains from non-browser processes.

T1071.004 high high confidence hunt now

Data: Sysmon Event ID 22

Indicators of compromise

2

domain

TypeValue
domainrouter.huggingface.co
domainapi.openai.com