A Cryptomining Campaign Targets Exposed AI Servers with Uncommon Malware Technique
A sophisticated cryptomining campaign has been discovered targeting exposed AI services, exploiting a unique method to spread malware and compromising thousands of servers worldwide. The PoeLLM malware, which has been active since at least April, uses an unusual technique to retrieve command-and-control (C2) addresses from a poem hosted on GitHub.
Researchers at Lumen’s Black Lotus Labs (BLL) have tracked the botnet malware, discovering that it has infected over 3,400 servers, with peak activity reaching as many as 800 compromised systems active on a single day. The operation targeted systems across the United States and Western Europe, with victims running exposed AI tools such as LiteLLM and Ollama.
The PoeLLM malware is notable for its use of a poem to retrieve C2 addresses. By extracting keywords from the “On the Nature of Connection” poem hosted in a GitHub repository, the malware generates an IP address corresponding to the C2 server. This technique allows the attackers to easily update the C2 address by modifying the poem, which has been done at least 11 times so far.
The malware itself incorporates remote-shell functionality, XMRig and Iron cryptocurrency miners, HTTP/S scanning, and exploit deployment capabilities. Once a server is compromised, it becomes a springboard for further spreading of the malware, using port scanning to identify vulnerable systems.
BLL researchers found that victims communicate with a Russian crypto-mining service called Kryptex. The attackers also reuse compromised routers in their attacks, leaving behind vulnerable router administration interfaces on several C2 servers.
The attribution of the operator is unclear, but BLL assesses with moderate confidence that they are likely Italian based on comments in the malware and an Italy-based server hosting the administrative interface.
To protect against PoeLLM attacks, system administrators should apply the latest security updates, reduce public internet exposure for critical assets, and restrict external access only to trusted IPs. Administrators should also inspect network monitoring logs and look for connections to the indicators of compromise (IoCs) shared by Black Lotus Labs.
As AI-powered systems become increasingly common, they are becoming attractive targets for threat actors due to their poor configuration, exposed online presence, and powerful GPU clusters suitable for cryptomining. This campaign serves as a reminder of the importance of securing AI services and reducing their exposure to the public internet.
Source: Bleeping Computer — 2026-10-07