PoeLLM malware infects exposed AI servers in cryptomining attacks
PoeLLM cryptomining malware has compromised over 2,100 exposed AI servers, using GitHub poems for command-and-control.
Lumen's Black Lotus Labs says PoeLLM has compromised more than 2,100 servers, with as many as 800 infections active in one day, mainly in the United States and Western Europe. Active since at least April 2026, the Linux malware derives its command-and-control IPv4 address from keywords in a GitHub-hosted poem and has used at least 11 controllers. Compromised hosts scan, deploy exploits, open a remote shell, and run XMRig and Iron miners associated with the Russian service Kryptex. Targets include exposed LiteLLM, Ollama, Gotenberg, and Gitea; CVE-2026-42271 can be chained with CVE-2026-48710 for unauthenticated LiteLLM remote code execution. Researchers moderately assess the operator as Italian.
- More than 2,100 servers compromised, with up to 800 active in one day.
- Command address is built from keywords in a GitHub-hosted poem.
- Targets exposed LiteLLM, Ollama, Gotenberg, Gitea, and Ivanti Sentry.
- Chains LiteLLM CVE-2026-42271 and CVE-2026-48710 for unauthenticated RCE.
- Operators assessed as likely Italian; mining ties to Russian service Kryptex.
Vulnerabilities mentionedAll →
- CVE-2026-422718.793%Command Injection in BerriAI LiteLLM AI Gateway Exploited in the Wildpublished · BerriAI LiteLLM (proxy server / AI Gateway) KEV
Full article552 words · extracted from bleepingcomputer.com · click to collapse

A cryptomining campaign targeting exposed AI services is using PoeLLM malware to turn compromised servers into scanners and exploit launchpads.
The malware features an uncommon method to retrieve command-and-control (C2) addresses by extracting keywords in a poem hosted on GitHub.
Researchers at Lumen's Black Lotus Labs (BLL) tracking the botnet malware say it has compromised more than 2,100 servers, with peak activity reaching as many as 800 infected systems active on a single day.
PoeLLM has been active since at least April, but its activity has increased significantly since then, with at least 11 C2 servers spun up to date.
According to the research, the operation targeted systems across the United States and Western Europe.

Source: Black Lotus Labs
Many of those victims run exposed AI tools such as LiteLLM and Ollama, the Gotenberg PDF converter, and the Gitea development toolkit, while signs of Ivanti Sentry targeting were also uncovered.
BLL notes that AI/LLM implementations are attractive targets for threat actors because they are often poorly configured, exposed online, and typically run on powerful GPU clusters that are suitable for cryptomining.
Poetry and malware
In a report today, BLL researchers say that PoeLLM, an ELF file named libgcrypt, retrieves four words or phrases from a poem titled “On the Nature of Connection” in a ‘dash.css’ file hosted in a GitHub repository that appears to fork Node.js.
It then maps these words to numbers using a hard-coded dictionary, generating a IPv4 address corresponding to the C2.

Source: Black Lotus Labs
To change the C2 address, the operator changes the poem. Until now, they have modified the poem 11 times, but researchers suspect that there may be at least another update.
The malware incorporates remote-shell functionality, XMRig and Iron cryptocurrency miners, HTTP/S scanning, and exploit deployment capabilities.
BLL researchers found that victims communicate with a Russian crypto-mining service called Kryptex.
Once a server is compromised, it becomes a springboard to spread the malware further, using scanning on ports 3000 and 4000, associated with Gotenberg and LiteLLM, and attempting to exploit CVE-2026-42271.
The CVE-2026-42271 vulnerability impacts LiteLLM’s MCP server test endpoints. It was originally disclosed as requiring authentication and received a high-severity score.
Horizon.ai researchers confirmed that it could be chained with another security issue, CVE-2026-48710, for unauthenticated remote code execution (RCE).

Source: Black Lotus Labs
By analyzing the infrastructure, BLL found that several C2 servers featured vulnerable router administration interfaces, suggesting that the attacker reused compromised routers in the attacks.
The researchers could not make a confident attribution but assess with moderate confidence that the operator is Italian, based on comments in the malware and an Italy-based server hosting the administrative interface.
To protect against PoeLLM attacks, system administrators should apply the latest security updates, reduce public internet exposure for critical assets, and restrict external access only to trusted IPs.
Administrators are recommended to inspect network monitoring logs and look for connections to the indicators of compromise (IoCs) shared by Black Lotus Labs.
Build your security blueprint for AI-powered attacks
Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.