ComfyUI Servers Compromised for Cryptomining and Botnet Operations

ComfyUI Servers Compromised for Cryptomining and Botnet Operations

First seen 8 Apr 2026, 10:03 UTC GbhackersHeise.DeScworld 79% similarity 74.0

Article Content

Browse articles
ThreatCluster

A significant wave of cyberattacks has targeted ComfyUI servers, converting them into a botnet for cryptomining and proxy operations. Researchers from Censys reported that since March 12, 2026, over 1,000 publicly accessible ComfyUI instances have been exploited by attackers. The attackers utilize a Python-based scanner to identify vulnerable servers and install malicious nodes without authentication. These compromised servers mine cryptocurrencies like Monero and Conflux, while being controlled via a Flask-based command-and-control dashboard. The malware employed is sophisticated, featuring evasion techniques and multiple revival mechanisms that persist through system reboots. ComfyUI, an open-source toolkit for AI image generation, is particularly vulnerable due to misconfigurations allowing public access. Administrators are advised to restrict access to these servers to internal networks or VPNs to mitigate risks. Detailed indicators of compromise (IOCs) have been provided for detection and prevention efforts.

Key Points: • Over 1,000 ComfyUI servers have been compromised for cryptomining and proxy operations. • Attackers exploit misconfigurations to install malware without authentication. • Sophisticated malware includes mechanisms to evade detection and persist after removal.

ThreatCluster AI

Timeline

2026-03-12
Wave of attacks on ComfyUI servers begins
2026-04-08
Censys reports over 1,000 compromised ComfyUI instances
2026-04-08
Detailed IOCs provided for ComfyUI administrators

Community

Browse all →