Attacker exploits misconfigured AI tool to run AI-generated payload
ID: 378d296e-2467-5a5b-88e7-48e4749defd9
STIX ID: report--378d296e-2467-5a5b-88e7-48e4749defd9
Feed Name: Sysdig Blog
Sysdig Threat Research Team observed attackers exploit a misconfigured, internet-exposed Open WebUI instance to upload an obfuscated, AI-assisted Python Tool that executed and deployed cryptominers (T-Rex, XMRig) on Linux and a sophisticated Java-based infostealer/loader on Windows. The malware employed strong defense-evasion techniques (compiled LD_PRELOAD processhider and an argv-hiding library), persisted via a masqueraded systemd service and JDK-based loader, used a Discord webhook for notifications/C2, and included numerous IoCs (file hashes, URLs, wallet addresses, and an IP).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
