Home · Wiki · Vulnerabilities & CVEs
type: cve · created: 2026-10-08 · updated: 2026-10-08 · tags: [cve] · confidence: medium · severity: high · affected_sectors: [global] · au_impact: false
🎯 IOCs · XMRIG
Indicators of compromise · XMRIG — 1 shown
  • 0ad68d5804804c25a6f6f3d87cc3a3886583f69b7115ba01ab7c6dd96a186404sha256 · ThreatFox · first seen 2026-09-25

Defanged third-party indicators (abuse.ch). The defanging is deliberate: never click, resolve or fetch these values. An indicator corroborates a report — it never proves one, and its presence here does not mean this story's hosts are listed.

Once inside, compromised servers run XMRig and Iron miners, communicate with the Russian mining service Kryptex, scan ports 3000/4000 and attempt to exploit CVE-2026-42271 in LiteLLM's MCP server endpoints — originally rated as requiring authentication until Horizon3 showed it chains with CVE-2026-48710 for unauthenticated RCE.

Attribute Detail
CVE CVE-2026-42271
CVSS 8.8 (HIGH)
Vendor / product BerriAI LiteLLM
Reported 2026-10-08