A new cryptomining campaign is exploiting exposed AI services using a malware called PoeLLM. The malware turns compromised servers into scanners and exploit launchpads, targeting systems in the United States and Western Europe. Researchers at Lumen's Black Lotus Labs (BLL) report that over 3,400 servers have been infected, with peak activity reaching 800 active systems on a single day.
PoeLLM has been active since at least April, with its activity increasing significantly. The malware uses an unusual method to retrieve command-and-control (C2) addresses by extracting keywords from a poem hosted on GitHub. The poem, titled 'On the Nature of Connection,' is stored in a 'dash.css' file within a GitHub repository. The malware maps these keywords to numbers using a hard-coded dictionary to generate an IPv4 address corresponding to the C2.
The campaign primarily targets exposed AI tools such as LiteLLM and Ollama, as well as the Gotenberg PDF converter and Gitea development toolkit. BLL notes that AI/LLM implementations are attractive targets due to their poor configuration, online exposure, and powerful GPU clusters suitable for cryptomining. Once a server is compromised, it becomes a springboard to spread the malware further, using scanning on ports 3000 and 4000 and attempting to exploit vulnerabilities like CVE-2026-42271 in LiteLLM.
To protect against PoeLLM attacks, system administrators are advised to apply the latest security updates, reduce public internet exposure for critical assets, and restrict external access to trusted IPs. They should also inspect network monitoring logs for connections to the indicators of compromise shared by Black Lotus Labs.