Pickai is a lightweight C++ backdoor targeting Linux systems, identified by XLab during exploitation of multiple high-risk vulnerabilities in the AI platform ComfyUI beginning in March 2025. Attackers delivered Pickai as ELF payloads disguised as configuration files such as config.json, tmux.conf, and vim.json. The malware supports remote command execution and reverse shell access, and its protocol uses 1024-byte messages including LISTEN| for command requests, UPDATE| for device information reporting, and STATUS| for C2 liveness checks; observed commands include EXECUTE and REVERSE.
Pickai includes several stealth and resilience features. It performs anti-debugging by checking TracerPid, enforces single-instance execution via a PID file, and uses prctl-based process-name spoofing with Linux-kernel-like names such as kworker/*, kblockd, and khugepaged. It establishes persistence through init.d or systemd depending on privilege level. When running as root, it copies itself to multiple locations including /usr/bin/auditlogd, /usr/sbin/hwstats, /sbin/dmesglog, /var/lib/autoupd, and /var/run/healthmon, and creates corresponding services such as auditlogd, hwstats, dmesglog, autoupd, and healthmon. When running as a non-root user, it persists through systemd user services under $HOME/.config/systemd/user/ and uses paths and service names including $HOME/.local/share/nano/nano, $HOME/.vim/vim, $HOME/.sshd/config/ssh.config, $HOME/.cache/mail/mail-sync, and $HOME/.gnome/config/gnome-X11. It appends random data to copied binaries to evade hash-based detection and decrypts embedded configuration strings from .rodata using XOR with 0xAF.
XLab reported that Pickai cycles through multiple hard-coded C2 servers and switches when higher-priority servers are unavailable. Known C2 infrastructure mentioned in the content includes h67t48ehfth8e.com, historyandresearch.com, and an earlier server at 195.43.6.252. XLab registered the unclaimed domain h67t48ehfth8e.com and collected telemetry indicating at least 695 compromised servers globally, with notable concentrations in Germany, the United States, and China. The content also states that Pickai samples were hosted on rubick.ai, creating potential supply-chain risk for Rubick.ai’s downstream e-commerce customers. Additional infrastructure noted includes a downloader hosted at 78.47.151.49 and a May 26, 2025 sample with MD5 8680f76a9faaa7f62967da8a66f5a59c. The content attributes exploitation activity to hacker groups but does not provide a specific named threat actor attribution.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A lightweight C++ backdoor providing remote command execution and reverse shell capability; includes anti-debugging, process name spoofing, and multiple persistence mechanisms; delivered by exploiting ComfyUI vulnerabilities and observed on compromised servers globally.
Lightweight Linux (ELF x86-64) C++ backdoor deployed via exploited ComfyUI vulnerabilities. Decrypts embedded configuration (XOR 0xAF), performs anti-debugging and single-instance checks, spoofs process names, establishes persistence via init.d/systemd (root and user modes) with multiple redundant copies, and communicates with hard-coded C2 infrastructure to request commands (EXECUTE) and establish reverse shells (REVERSE).
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.