PoeLLM Malware Targets Exposed AI Servers In Cryptomining Attacks

Researchers at Lumen's Black Lotus Labs have uncovered a cryptomining campaign that uses a new malware strain, PoeLLM, to hijack exposed AI servers. The operation turns compromised machines into cryptocurrency miners, forcing them to scan the internet and launch exploits against new victims.

According to the researchers, the botnet has infected more than 3,400 servers, and activity peaked at up to 800 systems in a single day. PoeLLM has stayed active since at least April 2026, and its operator has steadily expanded the infrastructure to at least 11 command-and-control servers.

PoeLLM Malware Targets Exposed AI Servers In Cryptomining Attacks

The campaign mainly targets organizations in the United States and Western Europe, where many companies now run self-hosted AI tools on internet-facing servers. Many victims operate exposed instances of LiteLLM and Ollama, while others run the Gotenberg PDF converter or the Gitea software development platform. The researchers also found signs that the operator targeted Ivanti Sentry appliances, which suggests the campaign casts a wider net than AI services alone.

Black Lotus Labs notes that AI deployments attract attackers because administrators often misconfigure them, expose them online, and run them on powerful GPU clusters. Those resources make compromised AI servers especially valuable to cybercriminals who want to mine cryptocurrency while victims pay for the hardware and power.

The threat actor began broad scanning and exploitation in May 2026, focusing heavily on exposed services tied to LiteLLM and the Gotenberg PDF converter. The malware primarily probes ports 3000 and 4000, which serve as the default listening ports for Gotenberg and LiteLLM deployments, respectively.

When a scan identifies a vulnerable target, an exploit server sends a POST request instructing the device to download a payload from port 81. Black Lotus Labs found that the targeted LiteLLM endpoint, /mcp-rest/test/connection, matches the exploitation path for the command injection flaw tracked as CVE-2026-42271.

CVE-2026-42271 affects the MCP server test endpoints in LiteLLM, and the April 2026 disclosure described it as a flaw that requires authentication. These endpoints accept a full server configuration, including commands and environment variables, and LiteLLM then spawns the supplied command as a subprocess.

However, Horizon3 researchers later showed that, when attackers chain the bug with CVE-2026-48710, "the authentication requirement can be bypassed entirely." The second flaw, nicknamed BadHost, lets attackers bypass Host header validation in Starlette, a Python web framework that LiteLLM relies on. Horizon3 rated the chained attack as a critical CVSS 10.0 issue because it grants unauthenticated attackers remote code execution on the LiteLLM host.

The affected releases include LiteLLM versions 1.74.2 through 1.83.6, as well as deployments whose dependency tree includes Starlette version 1.0.0 or earlier. LiteLLM fixed the problem in version 1.83.7 on May 8, 2026, which means PoeLLM's operator mainly preys on servers that administrators never update. According to Horizon3, successful exploitation of the vulnerability chain gives attackers several dangerous capabilities beyond simply dropping a cryptocurrency miner on the server:

  • Running arbitrary commands on the LiteLLM host with the privileges of the proxy process.
  • Accessing the credentials that LiteLLM uses to connect with AI model providers.
  • Stealing API keys and other secrets that the proxy stores.
  • Moving laterally into connected AI infrastructure and compromising downstream systems linked to the gateway.

Exposed Gotenberg servers present a similar problem, even though the project's installation guide explicitly warns users against exposing the service to the internet. Black Lotus Labs first spotted PoeLLM's infrastructure while investigating CVE-2026-10520, a vulnerability affecting Ivanti Sentry appliances, during early June 2026. A compromised Ivanti Sentry device contacted a PoeLLM command server and, shortly afterward, began scanning the internet for other vulnerable devices.

A Poem Points Bots to Their Masters

PoeLLM arrives as an ELF file named libgcrypt and bundles remote shell access, HTTP/HTTPS scanning, exploit deployment, and two cryptocurrency miners. The miners include XMRig and Iron, and infected servers connect to mining pools operated by Kryptex, a Russian cryptocurrency mining service.

The operator also turns infected machines into scanning and exploitation workers, so each new victim helps the botnet locate and compromise additional servers. More recently, groups of infected hosts have started probing SSH ports and login portals, suggesting the operator is testing a distributed brute-force framework.

The malware's most unusual feature is its method of finding command-and-control servers, which relies on a poem titled "On the Nature of Connection." The operator hides this poem inside a file named dash.css within a GitHub repository that forks the source code of the nodejs.org website.

PoeLLM extracts four keywords from fixed positions in the poem, converts each word into a number with a hard-coded dictionary, and builds an IPv4 address. In one example, the words driver, diode, decryption, and string translated into 92, 119, 165, and 74, pointing infected machines to 92.119.165[.]74.

Whenever the operator wants to move the botnet, they simply swap the four keywords, and every infected server automatically calculates the new address. The operator has edited the poem 11 times since the first commit on April 13, 2026, yet the parsing pattern itself has never changed. This approach makes takedowns harder because defenders cannot simply block a single hard-coded address, and GitHub traffic rarely raises suspicion on corporate networks.

Black Lotus Labs discovered that several PoeLLM command servers were running on routers with vulnerable administration interfaces, rather than on servers the attacker had leased. The first command server, which the operator likely used for testing, sat on a Brazilian router that exposed a Boa web server on port 2222.

A later command server in China showed the same pattern, which indicates the operator repeatedly hijacked weak routers to host malware and control victims. The researchers have now blocked all traffic to and from the known PoeLLM command servers, and they continue to monitor the botnet for new infrastructure.

The researchers could not make a confident attribution, but they assessed with moderate confidence that an Italian-speaking threat actor runs the operation. The malware sample that Black Lotus Labs analyzed contained code comments written in Italian, which provided one of the strongest clues about its origin.

Shortly after the first GitHub commit, the initial command server contacted an Italy-based server hosting malwarescan[.]xyz, a domain that someone registered in February 2026. Another Italian server, which previously hosted Prometheus and Uptime Kuma dashboards, likely serves as the operator's administrative panel for managing the entire botnet.

Black Lotus Labs warns that organizations often deploy AI tools quickly, yet they leave those tools outside normal patching and attack surface management processes. The researchers argue that, as companies expand their AI footprint, "the security of these agents cannot take a backseat to convenience."

Beyond cryptomining losses, unpatched AI servers can expose sensitive data, enable LLMjacking, and provide attackers with a foothold for lateral movement within corporate networks. Administrators running LiteLLM, Ollama, Gotenberg, Gitea, or Ivanti Sentry should review their deployments immediately and apply the following defensive measures:

  • Upgrade LiteLLM to version 1.83.7 or later, and update Starlette to version 1.0.1 or later.
  • Block access to LiteLLM's MCP test endpoints if immediate patching remains impossible, and rotate any credentials that the proxy stores.
  • Keep AI and developer services behind a firewall, and restrict external access to trusted IP addresses only.
  • Check network logs for connections to the indicators of compromise published by Black Lotus Labs on its GitHub page.
  • Patch and regularly reboot routers, firewalls, and IoT devices, since the operator abuses weak edge devices as command servers.

The PoeLLM campaign shows how quickly cybercriminals adapt to new technology, targeting AI servers for both their computing power and the valuable data they hold. Its poem-based command system also demonstrates that attackers will continue to invent creative ways to hide malicious infrastructure within trusted platforms like GitHub. Organizations that treat self-hosted AI tools like any other internet-facing application, with prompt patching and strict exposure controls, stand the best chance of avoiding infection.

Share:

facebook
X (Twitter)
linkedin
copy link
Karolis Liucveikis

Karolis Liucveikis

Experienced software engineer, passionate about behavioral analysis of malicious apps

Author and general operator of PCrisk's News and Removal Guides section. Co-researcher working alongside Tomas to discover the latest threats and global trends in the cyber security world. Karolis has experience of over 8 years working in this branch. He attended Kaunas University of Technology and graduated with a degree in Software Development in 2017. Extremely passionate about technical aspects and behavior of various malicious applications.

▼ Show Discussion

PCrisk security portal is brought by a company RCS LT.

Joined forces of security researchers help educate computer users about the latest online security threats. More information about the company RCS LT.

Our malware removal guides are free. However, if you want to support us you can send us a donation.

Donate