<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[(akamai.com) Sophisticated Go-Based P2P RAT and Cryptominer Targets AI Environments via Ollama API Exploitation]]></title><description><![CDATA[<p>(akamai.com) Sophisticated Go-Based P2P RAT and Cryptominer Targets AI Environments via Ollama API Exploitation</p><p>New Go-based P2P RAT/cryptominer targets AI environments via Ollama API exploitation (port 11434). Malware 'vc' uses libp2p for decentralized C2, evades detection with RAM disk storage, process renaming, and UPX obfuscation.</p><p>In brief - A sophisticated Go-based malware leverages Ollama API flaws to deploy a P2P RAT and XMRig miner, bypassing traditional defenses with decentralized networking and stealth techniques. AI environments are at risk due to supply chain and API exploitation.</p><p>Technically - The 'vc' binary (Go 1.25.7, UPX-packed with fake header) exploits Ollama’s `/api/create` endpoint to fetch `i.sh`, which deploys the payload. It uses libp2p (WebRTC/QUIC/DTLS/UPnP) for resilient P2P C2, stores itself in `/dev/shm/.udev-mesh-node`, and renames processes to `kworker`. Persistence via crontab, local mining proxy (127.0.0.1:41947), and 50% CPU-capped XMRig. Monitor outbound QUIC/WebSocket traffic for anomalies.</p><p>Source: <a href="https://www.akamai.com/blog/security-research/2026/may/stealthy-p2p-cryptominer-ollama-endpoints" rel="nofollow noopener"><span>https://www.</span><span>akamai.com/blog/security-resea</span><span>rch/2026/may/stealthy-p2p-cryptominer-ollama-endpoints</span></a></p><p><a href="https://swecyb.com/tags/Cybersecurity" rel="tag">#<span>Cybersecurity</span></a> <a href="https://swecyb.com/tags/ThreatIntel" rel="tag">#<span>ThreatIntel</span></a></p>]]></description><link>https://board.circlewithadot.net/topic/141653b5-b2ca-43ea-8227-684757ea0841/akamai.com-sophisticated-go-based-p2p-rat-and-cryptominer-targets-ai-environments-via-ollama-api-exploitation</link><generator>RSS for Node</generator><lastBuildDate>Mon, 25 May 2026 07:19:26 GMT</lastBuildDate><atom:link href="https://board.circlewithadot.net/topic/141653b5-b2ca-43ea-8227-684757ea0841.rss" rel="self" type="application/rss+xml"/><pubDate>Thu, 21 May 2026 22:25:21 GMT</pubDate><ttl>60</ttl></channel></rss>