OpenWebUI Servers Targeted in Attacks Using AI Payloads to Steal Data
ID: 85385a68-5204-508a-abf6-f4b7b07f2e5d
STIX ID: report--85385a68-5204-508a-abf6-f4b7b07f2e5d
Feed Name: GBHackers
**Executive Summary:** A campaign exploited internet-exposed, unauthenticated Open WebUI instances to upload an obfuscated AI-generated Python tool that delivered Linux cryptominers (T‑Rex, XMRig) and Windows infostealers via a Java loader; attackers used 64-layer Base64 obfuscation, PyObfuscator (pyklump), Discord webhook C2, LD_PRELOAD-based process and argv hiding, proxy-based downloads, and a disguised systemd service for persistence while targeting Monero/Kawpow mining and credential/token theft.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
