TrendAI researchers disclosed LF3, an unreported cryptomining and persistence framework targeting internet-exposed Langflow AI-workflow deployments through the POST /api/v1/validate/code endpoint. Honeypot telemetry logged 1,180 exploitation requests between May 2025 and July 2026, with LF3 operating across four build channels and producing three successful compromises on two sensors. The activity follows prior exploitation of Langflow’s critical CVE-2025-3248, which had been used to deploy the Flodrix botnet.
LF3 uses apt-update[.]com for custom HTTP command-and-control, installs a shell-based loader, attempts PwnKit privilege escalation, creates layered persistence, and deploys stock XMRig to mine Monero. Researchers cautioned that payloads sent to the code-validation route cannot be reliably assigned to CVE-2025-3248, CVE-2026-0770, or CVE-2026-0768 based solely on request structure because the vulnerabilities overlap on that endpoint; defenders should instead hunt for LF3’s C2 protocol and domain, stable configuration schema, hardcoded AES material, and loader artifacts.

See which actors are running it and whether you're in range.
6 events from the most recent confirmed update back to the earliest known activity.
A July LF3 compromise used an inline bootstrap that retrieved a loader from apt-update[.]com/ch and piped it directly to a shell.
An attacker gained access to a Langflow canary through CVE-2025-3248 and deployed a proxy agent, Chisel SOCKS5 tunnel, and pearl-miner XMR cryptominer. The operator later disabled auditd, exploited CVE-2026-0769 for persistence, scanned for additional targets, and pivoted over SSH.
A January LF3 compromise involved an interactive reverse shell, operator-led process enumeration and termination of competing malware, followed by manual deployment of the LF3 loader.
An LF3-related compromise used a socket stager connecting to 185[.]213[.]26[.]27 on TCP port 8881, followed by a Metasploit Meterpreter stage.
TrendAI honeypots recorded Langflow POST /api/v1/validate/code exploitation activity beginning May 13, ultimately capturing 1,180 requests from 70 source addresses through July 31, 2026.
The apt-update.com domain later used by the LF3 framework for custom HTTP command-and-control was registered.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 18 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
3 references tracked. Mallory keeps watching after this page renders.
vulncheck.com
Open sourcetrendaisecurity.com
Open sourcetrendmicro.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.