216.73.216.6

Beware of AI Pickpockets: Pickai Backdoor Spreading Through ComfyUI Vulnerability

· Published 13/06/2025 07:48 · Modified 13/06/2025 08:29

Export JSON

Essential information

Published
13/06/2025 07:48
Modified
13/06/2025 08:29
Tags
2025-06-13 ai data theft backdoor c2 comfyui evasion persistence pickai supply chain attack vulnerability
Related entities
9 observables, 8 techniques (mitre), 1 malware, 5 others

Description

A new named is exploiting vulnerabilities to spread and steal sensitive AI data. Developed in C++, offers remote command execution and reverse shell capabilities with strong and techniques. It uses multiple servers for redundancy and has infected nearly 700 devices globally. The malware is hosted on Rubick.ai, an AI e-commerce platform serving major brands, posing significant supply chain risks. employs various obfuscation methods, including string encryption, process disguise, and multiple mechanisms. Its network communication uses a three-tier timing strategy for communication and device information reporting.

External references