logo

SaaS-Style Cybercrime: Attackers Weaponize Langflow RCE and NATS Messaging for Ultra-Scalable C2

ID: cec53a09-cf35-5d8f-9b29-2776f121ae02

STIX ID: report--cec53a09-cf35-5d8f-9b29-2776f121ae02

Feed Name: securityonline.info

Threat Score
78/100

Date Published: 2026-05-18

Date Updated: 2026-05-18

Author: Ddos

...
...

Sysdig Threat Research Team uncovered an active campaign exploiting an unauthenticated RCE (CVE-2026-33017) in Langflow to install a Python worker and Go binary, attempt Linux privilege escalation (DirtyPipe, DirtyCreds), and connect to an authenticated, ACL-enforced NATS server (NATS-as-C2) that provides durable, scalable C2 via JetStream; observed IOCs include 45.192.109.25:14222 and 159.89.205.184:8888. The report details the novel use of NATS for operational security and scalability, and advises immediate mitigations: patch Langflow, restrict egress, block the listed endpoints, and rotate any exposed API keys.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.