Cybercriminals are increasingly turning their attention to artificial intelligence applications, exploiting critical vulnerabilities to gain access to corporate systems. According to new research from Trend Micro, a serious vulnerability in Langflow is already being used in real-world attacks aimed at mining software crypto, confirming that AI platforms are now a new arena for attackers.

The vulnerability, which has been recorded as CVE-2026-33017 and is rated 9.3/10 on the CVSS scale, allows remote code execution without any authentication process. Researchers observed the campaign over a 19-day period, from March 27 to April 15, 2026, with the attackers scanning the internet for exposed Langflow installations.
From a single line of code to a full-blown breach
The attack begins by executing a simple Python command via an unprotected Langflow API. This command downloads a remote shell script, which acts as a “dropper” and takes over the installation of the main malware.
The script first checks if the executable file “lambsys” already exists on the system. If it is not found, it downloads it via curl or wget, executes it in the background, and proceeds to the next phase of the attack.
See also: Langflow vulnerability used for RCE attacks
This binary is written in the Go language and is the main mechanism of the campaign, as it undertakes both the installation of the miner and the maintenance of access to the infected system.
Lambsys eliminates every obstacle
Trend Micro's analysis reveals that Lambsys is not limited to cryptocurrency mining. Before activating the miner, it disables a number of security mechanisms, including AppArmor, SELinux, iptables, Ubuntu Firewall, and even Alibaba Cloud protection services.
At the same time, it terminates competing cryptojacking programs, including Kinsing, WatchDog, Rocke , and Outlaw, deleting their files and wallets so that it can exclusively exploit system resources.
The malware also creates persistence mechanisms via cron jobs, removes log files to hide its tracks, and modifies critical Linux files, even using the chattr +i, which makes certain files immutable even for the system administrator.
Deploying via SSH and installing XMRig
One of the most worrying features of the campaign is its ability to spread laterally within the corporate network. Lambsys attempts to leverage existing SSH keys to gain access to other servers where it has valid credentials.
After completing the necessary changes to the system, it contacts a command and control server to download a compressed TAR file containing a customized version of the miner XMRig. After its installation, the file is automatically deleted, reducing the traces left behind by the attack.
At the same time, the malware communicates with the ipinfo.io to collect information about the victim's public IP and geographic location.
See also: Hackers exploit critical RCE flaw in Langflow

Why does the victim's location matter?
Location information is not collected randomly. Attackers use this data to select the nearest mining pool, reducing network latency and increasing mining efficiency.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
In addition, they implement geo-blocking practices, avoiding infecting systems in specific countries, either to limit the risk of detection or to avoid legal consequences.
AI applications become a new target
Trend Micro estimates that this malware family has been evolving for at least two years, as older versions of the same executable have been detected since 2024. The constant updating of the code shows that its creators are systematically investing in avoiding detection by security solutions.
See also: Langflow vulnerability exploited by Flodrix Botnet
This is not the first time Langflow has been the focus of attacks. In 2025, a different critical vulnerability was exploited to distribute the Flodrix, demonstrating that AI application development platforms are becoming attractive targets for cybercriminals.
The new campaign is yet another reminder that rapid adoption of AI tools must be matched by equally rapid implementation of security updates. As more and more businesses integrate such platforms into their infrastructures, cybercriminals are constantly looking for new ways to exploit security gaps, turning AI applications into one of the most important new entry points for cyberattacks.
