Back to Feed
MalwareOct 7, 2026

PoeLLM malware infects exposed AI servers in cryptomining attacks

PoeLLM malware targets exposed AI servers for cryptomining, using a poem for C2.

Summary

A new cryptomining campaign, dubbed PoeLLM, is exploiting exposed AI servers, compromising over 3,400 systems. The malware uniquely retrieves C2 addresses by extracting keywords from a poem hosted on GitHub, allowing operators to change the C2 infrastructure by modifying the poem. It includes cryptomining capabilities, remote shell access, and exploit deployment, targeting AI tools like LiteLLM and Ollama.

Full text

PoeLLM malware infects exposed AI servers in cryptomining attacks By Bill Toulas October 7, 2026 11:04 AM 0 A cryptomining campaign targeting exposed AI services is using PoeLLM malware to turn compromised servers into scanners and exploit launchpads. The malware features an uncommon method to retrieve command-and-control (C2) addresses by extracting keywords in a poem hosted on GitHub. Researchers at Lumen's Black Lotus Labs (BLL) tracking the botnet malware say it has compromised more than 3,400 servers, with peak activity reaching as many as 800 infected systems active on a single day. PoeLLM has been active since at least April, but its activity has increased significantly since then, with at least 11 C2 servers spun up to date. According to the research, the operation targeted systems across the United States and Western Europe. Victims of PoeLLMSource: Black Lotus Labs Many of those victims run exposed AI tools such as LiteLLM and Ollama, the Gotenberg PDF converter, and the Gitea development toolkit, while signs of Ivanti Sentry targeting were also uncovered. BLL notes that AI/LLM implementations are attractive targets for threat actors because they are often poorly configured, exposed online, and typically run on powerful GPU clusters that are suitable for cryptomining. Poetry and malware In a report today, BLL researchers say that PoeLLM, an ELF file named libgcrypt, retrieves four words or phrases from a poem titled “On the Nature of Connection” in a ‘dash.css’ file hosted in a GitHub repository that appears to fork Node.js. It then maps these words to numbers using a hard-coded dictionary, generating a IPv4 address corresponding to the C2. The poem used for C2 address constructionSource: Black Lotus Labs To change the C2 address, the operator changes the poem. Until now, they have modified the poem 11 times, but researchers suspect that there may be at least another update. The malware incorporates remote-shell functionality, XMRig and Iron cryptocurrency miners, HTTP/S scanning, and exploit deployment capabilities. BLL researchers found that victims communicate with a Russian crypto-mining service called Kryptex. Once a server is compromised, it becomes a springboard to spread the malware further, using scanning on ports 3000 and 4000, associated with Gotenberg and LiteLLM, and attempting to exploit CVE-2026-42271. The CVE-2026-42271 vulnerability impacts LiteLLM’s MCP server test endpoints. It was originally disclosed as requiring authentication and received a high-severity score. Horizon.ai researchers confirmed that it could be chained with another security issue, CVE-2026-48710, for unauthenticated remote code execution (RCE). PoeLLM attack overviewSource: Black Lotus Labs By analyzing the infrastructure, BLL found that several C2 servers featured vulnerable router administration interfaces, suggesting that the attacker reused compromised routers in the attacks. The researchers could not make a confident attribution but assess with moderate confidence that the operator is Italian, based on comments in the malware and an Italy-based server hosting the administrative interface. To protect against PoeLLM attacks, system administrators should apply the latest security updates, reduce public internet exposure for critical assets, and restrict external access only to trusted IPs. Administrators are recommended to inspect network monitoring logs and look for connections to the indicators of compromise (IoCs) shared by Black Lotus Labs. Update [11:40 EST]: Corrected the number of compromised servers. Original report received by BleepingComputer stated that 2,100 servers were compromised but the researchers updated the number to 3,400 in the live report. Build your security blueprint for AI-powered attacks Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed. Save your seat Related Articles: New Carbonato malware uses AI agents to hijack exposed Docker hostsNew ClosedQuorum Windows malware uses AI for attack decisionsNew RatHat Android malware uses AI to automate device controlMusician sent to prison for $10 million streaming fraud using AI botsWikimedia: Rogue OpenAI agents behind unauthorized Wikipedia edits

Indicators of Compromise

  • cve — CVE-2026-42271
  • cve — CVE-2026-48710

Entities

LiteLLM (product)Ollama (product)Gotenberg (product)Gitea (product)Ivanti Sentry (product)