Cryptomining malware targets exposed AI servers worldwide

PoeLLM botnet infects over 3,400 systems using a poem hidden on GitHub to fetch command-and-control addresses

By LineZotpaper
Published
Read Time2 min
A cryptomining campaign codenamed PoeLLM has infected more than 3,400 exposed AI servers, using a poem stored on GitHub to generate its command-and-control addresses, according to researchers at Lumen's Black Lotus Labs. The malware has been active since at least April and has primarily targeted poorly configured AI tools such as LiteLLM and Ollama, turning compromised systems into launchpads for further attacks and cryptocurrency mining.

Researchers at Lumen's Black Lotus Labs (BLL) have been tracking a cryptomining campaign they call PoeLLM. The malware, an ELF file named libgcrypt, compromises servers running exposed AI tools and services, including LiteLLM, Ollama, the Gotenberg PDF converter, and the Gitea development toolkit. Signs of targeting against Ivanti Sentry were also observed.

The malware uses an unusual method to contact its command-and-control (C2) infrastructure. It retrieves four words or phrases from a poem titled "On the Nature of Connection" contained in a CSS file hosted on a GitHub repository. A hard-coded dictionary then maps those words to numbers that form an IPv4 address. The operator can change the poem to alter the C2 address, and the researchers have observed 11 different C2 servers so far, with the poem modified 11 times.

Once installed, PoeLLM enables remote shell access, deploys XMRig and Iron cryptocurrency miners, and includes HTTP/S scanning and exploit capabilities. The infected servers are used as springboards to spread further, scanning ports 3000 and 4000 associated with Gotenberg and LiteLLM. The malware attempts to exploit CVE-2026-42271, a high-severity vulnerability in LiteLLM's MCP server test endpoints, which researchers at Horizon.ai confirmed can be chained with another issue, CVE-2026-48710, for unauthenticated remote code execution.

BLL reports peak activity of up to 800 infected systems active on a single day, with victims concentrated across the United States and Western Europe. The researchers found that compromised servers communicate with a Russian crypto-mining service called Kryptex. The botnet appears to be under active development, with evidence suggesting at least another update may be forthcoming.

AI and large language model implementations are attractive targets for threat actors because they often run on powerful GPU clusters suitable for cryptomining and are frequently misconfigured and exposed online, the researchers noted.

§

Analysis

Why This Matters

  • The attack exploits a common weakness: AI infrastructure is often deployed rapidly without proper hardening, leaving GPU-rich servers exposed.
  • Compromised servers not only consume resources for mining but can become stepping stones for further attacks on internal networks.
  • The use of a poem to obscure C2 addresses shows an evolving sophistication in malware operational security.

Background

Cryptomining malware has long targeted high-compute resources, but the rapid deployment of AI services has created a new class of targets. Many organizations expose inference endpoints and development tools without adequate access controls, often because these services are intended for internal use but are accidentally left internet-facing. The PoeLLM campaign follows a pattern seen with other botnets like FritzFrog but adds novel obfuscation techniques.

Key Perspectives

Security researchers (Black Lotus Labs): They highlight the growing threat to AI infrastructure and the need for better configuration management. The campaign is active, evolving, and likely to expand. AI service operators: Those running exposed tools such as LiteLLM or Ollama are directly at risk. The vulnerability CVE-2026-42271, if unpatched, provides an entry point even when services are partially secured. Attackers: The operation's use of a Russian mining pool and poem-based C2 suggests a well-funded or technically sophisticated group that values stealth and resilience.

What to Watch

  • Patching of CVE-2026-42271 and CVE-2026-48710 by affected vendors and organizations.
  • Changes to the poem in the GitHub repository, which would signal C2 rotation or expansion.
  • Infection counts and geographic spread as the botnet may target new regions or services.

Sources

Zotpaper

Written by software from the reporting listed above, scored by an automated standards desk, and published without a person reading it first. If something here is wrong, tell the editor and it will be put right.