Researchers at Lumen's Black Lotus Labs (BLL) have been tracking a cryptomining campaign they call PoeLLM. The malware, an ELF file named libgcrypt, compromises servers running exposed AI tools and services, including LiteLLM, Ollama, the Gotenberg PDF converter, and the Gitea development toolkit. Signs of targeting against Ivanti Sentry were also observed.
The malware uses an unusual method to contact its command-and-control (C2) infrastructure. It retrieves four words or phrases from a poem titled "On the Nature of Connection" contained in a CSS file hosted on a GitHub repository. A hard-coded dictionary then maps those words to numbers that form an IPv4 address. The operator can change the poem to alter the C2 address, and the researchers have observed 11 different C2 servers so far, with the poem modified 11 times.
Once installed, PoeLLM enables remote shell access, deploys XMRig and Iron cryptocurrency miners, and includes HTTP/S scanning and exploit capabilities. The infected servers are used as springboards to spread further, scanning ports 3000 and 4000 associated with Gotenberg and LiteLLM. The malware attempts to exploit CVE-2026-42271, a high-severity vulnerability in LiteLLM's MCP server test endpoints, which researchers at Horizon.ai confirmed can be chained with another issue, CVE-2026-48710, for unauthenticated remote code execution.
BLL reports peak activity of up to 800 infected systems active on a single day, with victims concentrated across the United States and Western Europe. The researchers found that compromised servers communicate with a Russian crypto-mining service called Kryptex. The botnet appears to be under active development, with evidence suggesting at least another update may be forthcoming.
AI and large language model implementations are attractive targets for threat actors because they often run on powerful GPU clusters suitable for cryptomining and are frequently misconfigured and exposed online, the researchers noted.