PoeLLM malware hijacks exposed AI servers for cryptomining
A botnet called PoeLLM is compromising internet-facing AI services and turning them into cryptomining nodes, scanners and launch points for further attacks, according to Lumen's Black Lotus Labs (BLL).
The researchers say the malware has infected more than 3,400 servers. On its busiest day, as many as 800 infected systems were active at once. The initial report put the number of compromised servers at 2,100, but the researchers later raised it to 3,400.
PoeLLM has been active since at least April. Its activity has grown considerably since then, and the operator has set up at least 11 command-and-control (C2) servers so far.
Who is being targeted
The campaign has focused on systems in the United States and Western Europe. Many victims run exposed AI tools such as LiteLLM and Ollama. Others run the Gotenberg PDF converter or the Gitea development toolkit. Researchers also found signs that Ivanti Sentry systems were targeted.
BLL explains why AI and LLM deployments are attractive to attackers. They are often poorly configured and exposed online, and they usually run on powerful GPU clusters that are well suited to cryptomining.
A poem as a C2 locator
The malware is an ELF file named libgcrypt. To find its C2 server, PoeLLM reads a poem called "On the Nature of Connection." The poem sits in a file named 'dash.css' in a GitHub repository that appears to be a fork of Node.js.
The malware pulls four words or phrases out of the poem. It then converts them into numbers using a hard-coded dictionary, and the result is the IPv4 address of the C2 server.
This means the operator only has to edit the poem to point the botnet at a new server. The poem has been changed 11 times so far, and the researchers suspect at least one more update may exist.
Capabilities and spreading
PoeLLM bundles several functions:
- remote shell access
- the XMRig and Iron cryptocurrency miners
- HTTP/S scanning
- exploit deployment
BLL found that infected machines communicate with Kryptex, a Russian cryptomining service.
Each compromised server is also used to spread the malware further. It scans ports 3000 and 4000, which are associated with Gotenberg and LiteLLM, and tries to exploit CVE-2026-42271.
That flaw affects test endpoints of LiteLLM's MCP server. It was first disclosed as a high-severity bug that required authentication. Researchers at Horizon.ai later confirmed that it can be chained with a second issue, CVE-2026-48710, to achieve unauthenticated remote code execution (RCE).
Infrastructure and attribution
When BLL looked at the attacker's infrastructure, it found that several C2 servers had vulnerable router administration interfaces. This suggests the operator reused compromised routers to run the campaign.
The researchers could not attribute the attacks with confidence. However, they assess with moderate confidence that the operator is Italian. This is based on comments left in the malware and on an Italy-based server that hosts the administrative interface.
Defending against PoeLLM
BLL advises administrators to install the latest security updates and to limit how much critical infrastructure is reachable from the public internet. External access should be restricted to trusted IP addresses.
Teams should also review their network monitoring logs for connections to the indicators of compromise (IoCs) published by Black Lotus Labs.
Our Take
PoeLLM shows how quickly self-hosted AI tooling has become part of the regular attack surface. LiteLLM gateways and Ollama instances are often deployed fast for testing and left open. Since they usually sit on expensive GPU hardware, they are an obvious prize for cryptominers. This fits a broader pattern we have covered, including reports that attacks on AI systems are outpacing corporate readiness.
The poem-based C2 lookup is a reminder that malware authors keep hiding in trusted platforms such as GitHub, where the traffic looks harmless. Like the ClingSTUN Linux backdoor, PoeLLM pairs unusual communication tricks with known-flaw exploitation to grow.
The LiteLLM bug chain is also worth noting. A flaw first rated as requiring authentication turned out to allow unauthenticated RCE. It is worth watching whether other operators adopt this chain, and whether the botnet expands to target more AI frameworks. Teams running AI services should treat them like any other exposed server and patch and firewall them accordingly.
