logo

Open WebUI Misconfiguration Exploited for Cryptojacking (Campaign)

ID: 102a1cdd-2464-5fd7-a779-3468265814c8

STIX ID: report--102a1cdd-2464-5fd7-a779-3468265814c8

Feed Name: Wiz Cloud Threat Landscape

Threat Score
70/100

Date Published: 2025-06-03

Date Updated: 2026-05-01

Author: [email protected] (Wiz Threat Research)

...
...

Researchers observed an active exploitation of an internet-exposed, misconfigured Open WebUI instance (admin access with no authentication) where an attacker uploaded an AI-assisted, heavily obfuscated Python payload that deployed Linux cryptominers (T-Rex, XMRig), compiled stealth tools (processhider, argvhider), established persistence via systemd, and used a Discord webhook for C2; a Windows secondary stage delivered a malicious JAR via a JDK installer that dropped Java loaders and DLLs performing credential theft, sandbox evasion, and reconnaissance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.