logo

AI Honeypots Snare Decentralized Cryptominer Dropper

ID: 3a391502-8c9f-5649-acac-08223dc01d31

STIX ID: report--3a391502-8c9f-5649-acac-08223dc01d31

Feed Name: securityonline.info

Threat Score
70/100

Date Published: 2026-06-01

Date Updated: 2026-06-01

Author: Ddos

...
...

Akamai analysts discovered a sophisticated fileless P2P cryptominer campaign that scans for exposed Ollama/LLM API ports (notably 11434) to deploy an automated installer (i.sh), execute a custom Go-built binary with an integrated libp2p stack, and run a throttled XMRig Monero miner while evading detection via process impersonation and memory-only execution; persistence is maintained through a root crontab that restarts the miner every 15 minutes and defenders are advised to monitor outbound connections, block unauthorized QUIC/443 flows, and inspect unusual memory paths.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.