PoeLLM Malware Targets Exposed AI Servers in Cryptomining Campaign
A cryptomining campaign is targeting exposed AI services with PoeLLM malware, turning compromised servers into scanners and launching platforms for further attacks.
The malware uses an unusual method to obtain command-and-control (C2) addresses: it extracts keywords from poems hosted on GitHub.
Researchers at Lumen’s Black Lotus Labs (BLL), which tracks the botnet, say PoeLLM has compromised more than 2,100 servers. As many as 800 infected systems were active each day at the campaign’s peak.
PoeLLM has been active since at least April, and its activity has increased significantly since then. At least 11 C2 servers have been identified to date.
According to the investigation, the campaign targeted systems across the United States and Western Europe.

Source: Black Lotus Labs
Exposed AI tools targeted by PoeLLM
Many victims were running publicly available AI and developer tools, including LiteLLM, Ollama, Gotenberg PDF converter, and Gitea. BLL also found indications that Ivanti Sentry was targeted.
Black Lotus Labs says AI and large language model (LLM) implementations are often poorly configured and exposed to the internet. These systems are attractive targets because they commonly run on powerful GPU clusters that can be repurposed for cryptomining.
Malware hides C2 addresses in GitHub poetry
According to BLL’s report, PoeLLM is an ELF file named libgcrypt. It retrieves four words or phrases from a poem titled “On the Nature of Connections,” located in the dash.css file of a GitHub repository that appears to be a fork of Node.js.
The malware uses a hard-coded dictionary to map those words to numbers, generating the corresponding IPv4 address for its C2 server.

Source: Black Lotus Labs
Operators can change the C2 address by modifying the poem. Researchers say the poem has been revised 11 times so far and suspect it will be updated again.
PoeLLM combines cryptominers with scanning and exploitation
The malware includes remote shell functionality, the XMRig and Iron cryptocurrency miners, HTTP and HTTPS scanning, and exploit deployment capabilities.
BLL researchers found that infected systems communicated with Kryptex, a Russian cryptocurrency mining service.
After compromising a server, PoeLLM uses it as a springboard to spread through network scanning. The malware targets ports 3000 and 4000, which are associated with Gotenberg and LiteLLM, and attempts to exploit CVE-2026-42271.
CVE-2026-42271 affects the LiteLLM MCP Server test endpoint. The vulnerability was originally published as requiring authentication and received a high severity score.
Horizon.ai reported that the vulnerability may be linked to another unauthenticated remote code execution (RCE) issue, CVE-2026-48710.

Source: Black Lotus Labs
Compromised routers may support the campaign
After analyzing its infrastructure, BLL discovered that several C2 servers had vulnerable router management interfaces. This suggests that the attackers reused compromised routers during the campaign.
Researchers could not identify the operator with confidence. However, they assessed that the operator may be Italian based on comments in the malware and an Italy-based server hosting the administrative interface.
How to protect systems from PoeLLM
To reduce the risk of PoeLLM attacks, system administrators should apply the latest security updates, minimize the public exposure of critical assets, and restrict external access to trusted IP addresses wherever possible.
Administrators should also review network monitoring logs and check for connections to the indicators of compromise (IoCs) shared by Black Lotus Labs.
Join Mikko Hypponen and security leaders from the NFL, Chanel, and Atlassian for a two-hour digital summit about what will change with AI-speed attacks, what defenders should stop doing, and how to verify, decide, fix, and revalidate at machine speed.
Source: www.bleepingcomputer.com



