Researchers reported an active campaign exploiting more than 1,000 internet-exposed ComfyUI instances, especially deployments running without authentication and those using unsafe custom nodes or ComfyUI-Manager, to gain unauthenticated remote code execution. The attackers used a purpose-built Python scanning pipeline to sweep cloud IP ranges, identify vulnerable systems, and deploy a payload known as ghost.sh, then monetized access by installing XMRig for Monero mining and lolMiner for Conflux mining while also enrolling compromised hosts into a Hysteria v2 proxy botnet controlled through a Flask-based command-and-control panel.
The operation showed extensive persistence and defense-evasion tradecraft, including fileless execution via memfd_create, process masquerading, an LD_PRELOAD rootkit for process hiding, watchdog-based restoration, scattered backups, and immutable file locking. Investigators also found reinfection mechanisms in newer scanner versions, including a fake "GPU Performance Monitor" custom node that re-downloads the payload every six hours and a poisoned default startup workflow that relaunches it whenever ComfyUI restarts. Infrastructure tied to 77.110.96[.]200 and additional SSH-linked hosts across China Mobile, DigitalOcean, and AWS suggests a broader opportunistic campaign that may overlap with activity targeting other exposed services such as Redis.

Map this exposure pattern across your cloud, code, and identities.
4 events from the most recent confirmed update back to the earliest known activity.
Censys ARC published research detailing the campaign, including the ghost.sh payload, Flask-based command-and-control panel, and persistence and evasion techniques such as memfd_create execution, LD_PRELOAD process hiding, watchdog restoration, and immutable file locking. The report said more than 1,000 exposed ComfyUI instances were being targeted.
Censys identified infrastructure centered on 77.110.96.200, with related SSH-linked hosts in China Mobile, DigitalOcean, and AWS networks. The findings suggested a wider opportunistic exploitation effort, including possible overlap with activity targeting exposed Redis servers.
The campaign's purpose-built scanner reached version 8.2 and added two persistence features: a fake "GPU Performance Monitor" custom node that re-downloads the payload every six hours and a poisoned default startup workflow that re-executes the malware when ComfyUI restarts. These additions strengthened reinfection and long-term access on compromised hosts.
An active campaign targeted internet-exposed ComfyUI deployments, especially unauthenticated instances with unsafe custom nodes or ComfyUI-Manager installed, to achieve remote code execution. Compromised systems were used for Monero and Conflux mining and enrolled into a Hysteria v2 proxy botnet.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 16 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See where this exposure pattern shows up across your cloud, code, supply chain, and non-human identities.
3 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcethehackernews.com
Open sourcecensys.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.