A cryptomining campaign targeting exposed AI services is using PoeLLM malware to turn compromised servers into scanners and exploit launchpads. Researchers at Lumen's Black Lotus Labs tracking the botnet malware say it has compromised more than 3,400 servers, with peak activity reaching as many as 800 infected systems active on a single day. PoeLLM has been active since at least April, but its activity has increased significantly since then, with at least 11 command-and-control servers spun up to date. According to the research, the operation targeted systems across the United States and Western Europe.
Many of those victims run exposed AI tools such as LiteLLM and Ollama, the Gotenberg PDF converter, and the Gitea development toolkit, while signs of Ivanti Sentry targeting were also uncovered. Black Lotus Labs notes that AI and large language model implementations are attractive targets for threat actors because they are often poorly configured, exposed online, and typically run on powerful GPU clusters that are suitable for cryptomining. In a report, the researchers say that PoeLLM, an ELF file named libgcrypt, retrieves four words or phrases from a poem titled On the Nature of Connection in a dash.css file hosted in a GitHub repository that appears to fork Node.js.
Malware extracts command addresses from a poem
The malware then maps these words to numbers using a hard-coded dictionary, generating an IPv4 address corresponding to the command-and-control server. To change the address, the operator changes the poem. Until now, they have modified the poem 11 times, but researchers suspect that there may be at least another update. The malware incorporates remote-shell functionality, XMRig and Iron cryptocurrency miners, HTTP/S scanning, and exploit deployment capabilities. Black Lotus Labs researchers found that victims communicate with a Russian crypto-mining service called Kryptex.
Once a server is compromised, it becomes a springboard to spread the malware further, using scanning on ports 3000 and 4000, associated with Gotenberg and LiteLLM, and attempting to exploit CVE-2026-42271. The CVE-2026-42271 vulnerability impacts LiteLLM's MCP server test endpoints. It was originally disclosed as requiring authentication and received a high-severity score. Horizon.ai researchers confirmed that it could be chained with another security issue, CVE-2026-48710, for unauthenticated remote code execution. By analyzing the infrastructure, researchers found that several command-and-control servers featured vulnerable router administration interfaces, suggesting that the attacker reused compromised routers in the attacks.
Administrators should apply security updates
The researchers could not make a confident attribution but assess with moderate confidence that the operator is Italian, based on comments in the malware and an Italy-based server hosting the administrative interface. To protect against PoeLLM attacks, system administrators should apply the latest security updates, reduce public internet exposure for critical assets, and restrict external access only to trusted IPs. Administrators are recommended to inspect network monitoring logs and look for connections to the indicators of compromise shared by Black Lotus Labs.



