logo

OpenWebUI Servers Targeted in Attacks Using AI Payloads to Steal Data

ID: 85385a68-5204-508a-abf6-f4b7b07f2e5d

STIX ID: report--85385a68-5204-508a-abf6-f4b7b07f2e5d

Feed Name: GBHackers

Threat Score
75/100

Date Published: 2026-03-19

Date Updated: 2026-04-22

Author: Divya

...
...

**Executive Summary:** A campaign exploited internet-exposed, unauthenticated Open WebUI instances to upload an obfuscated AI-generated Python tool that delivered Linux cryptominers (T‑Rex, XMRig) and Windows infostealers via a Java loader; attackers used 64-layer Base64 obfuscation, PyObfuscator (pyklump), Discord webhook C2, LD_PRELOAD-based process and argv hiding, proxy-based downloads, and a disguised systemd service for persistence while targeting Monero/Kawpow mining and credential/token theft.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.