Cybersecurity

PoeLLM Malware Infects Thousands of AI Servers to Mine Cryptocurrency

Black Lotus Labs researchers uncovered a covert mining campaign that exploited more than 3,400 exposed servers, including systems running LiteLLM and Ollama, and turned infected devices into platforms for scanning new targets and carrying out attacks. The malware uses an unusual mechanism to extract command-and-control server addresses from hidden words in a poem hosted on GitHub.

2026-10-07
4 min read
0 views
certi.news Editorial Team
PoeLLM Malware Infects Thousands of AI Servers to Mine Cryptocurrency

Researchers at Lumen’s Black Lotus Labs said that malware named PoeLLM was used in a cryptocurrency-mining campaign that infected more than 3,400 servers, with a peak of approximately 800 active infected systems recorded in a single day. According to the investigation, the campaign’s activity began in April but later intensified, with at least 11 command-and-control servers operating.

The operation targeted servers in the United States and Western Europe. Affected systems included internet-exposed artificial intelligence services such as LiteLLM and Ollama, as well as the Gotenberg PDF converter and the Gitea development tool. Researchers also found indicators warranting investigation into the targeting of Ivanti Sentry.

A Poem Becomes a Command-and-Control Server Address

PoeLLM, an ELF file named libgcrypt, uses an unusual method to obtain the command-and-control server address. It reads four words or phrases from a poem titled “On the Nature of Connection” inside a dash.css file hosted in a GitHub repository that appears to be a derivative of Node.js, then converts those words into numbers using an embedded dictionary to generate an IPv4 address.

This method allows the operator to change the command-and-control server address by modifying the poem itself. Researchers have identified 11 modifications so far, with the possibility that another update has not yet been documented.

Infected Servers Become Propagation Platforms

The malware is not limited to running mining tools. It includes a remote shell function, XMRig and Iron miners, capabilities for scanning HTTP and HTTPS services, and exploit deployment capabilities. Black Lotus Labs found that some victims connect to the Russian Kryptex service to mine cryptocurrency.

After compromising a server, the campaign uses it as a launch point to search for new victims by scanning ports 3000 and 4000, which are associated with Gotenberg and LiteLLM services, and attempting to exploit CVE-2026-42271 in LiteLLM’s MCP test endpoints. The vulnerability was initially disclosed as requiring authentication and received a high severity rating, but Horizon.ai researchers confirmed that it could be chained with CVE-2026-48710 to achieve unauthenticated remote command execution.

Why Does This Matter?

The campaign shows that exposed AI servers are not merely targets for mining because of their computing power; they can also become tools for scanning networks and expanding infections. The risk is greater when the service is poorly configured or directly accessible from the internet, particularly in environments that rely on powerful GPU units.

Researchers also found that some command-and-control servers contained weak router administration interfaces, suggesting that compromised routers were reused within the attack infrastructure. They were unable to confidently attribute the campaign to a specific actor, but assessed with medium confidence that the operator is Italian, based on comments inside the malware and a server hosting the administration interface in Italy.

What Should Administrators Do?

Black Lotus Labs recommends installing the latest security updates, reducing the exposure of sensitive assets to the public internet, and restricting external access to trusted IP addresses. Administrators should also review network monitoring logs and look for connections associated with the indicators of compromise published by the researchers.

BleepingComputer corrected the number of infected servers in a subsequent update, revising it from 2,100 to 3,400 after the researchers updated their live report.

News source
BleepingComputer
Open original source ↗
c
Author

certi.news Editorial Team

In the same category

You may also like

View all news