logo

Over 1,000 Exposed ComfyUI Instances Targeted in Cryptomining Botnet Campaign

ID: 3b7bcd24-0d42-5d50-9db9-dc245d827022

STIX ID: report--3b7bcd24-0d42-5d50-9db9-dc245d827022

Feed Name: The Hacker News

Threat Score
75/100

Date Published: 2026-04-07

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

Censys researchers uncovered an active campaign that scans cloud IP ranges for exposed ComfyUI instances and weaponizes unsafe custom nodes or ComfyUI-Manager to achieve unauthenticated remote code execution; compromised hosts are used for Monero and Conflux mining (XMRig, lolMiner) and recruited into a Hysteria V2 proxy botnet controlled via a Flask C2. The attacker uses purpose-built Python scanners, a malicious ComfyUI package (ComfyUI-Shell-Executor) that fetches a ghost.sh payload, persistence techniques (periodic downloads, LD_PRELOAD watchdog, chattr +i), competitor miner takeover, and multiple fallback installations; Censys observed repository tooling, IP indicators, and linkage to broader botnet activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.