Cryptomining Campaign Exploits Exposed AI Servers with Unconventional Malware Technique
A sophisticated cryptomining campaign has been targeting exposed AI services, compromising over 3,400 servers and using an unusual method to retrieve command-and-control (C2) addresses. The malware, named PoeLLM, leverages a poem hosted on GitHub to extract keywords that are then used to generate C2 addresses.
The operation appears to be focused on systems in the United States and Western Europe, with many victims running exposed AI tools such as LiteLLM and Ollama. Researchers at Lumen’s Black Lotus Labs (BLL) have been tracking the botnet malware, noting that its activity has increased significantly since April. The team estimates that at least 11 C2 servers have been spun up to date.
What makes PoeLLM particularly noteworthy is its use of a poem to generate C2 addresses. By extracting four specific words or phrases from the poem “On the Nature of Connection,” the malware maps them to numbers using a hard-coded dictionary, ultimately generating an IPv4 address corresponding to the C2 server. The operator can change the C2 address by modifying the poem, which has been updated at least 11 times.
The malware itself incorporates various malicious capabilities, including remote-shell functionality, cryptocurrency mining (XMRig and Iron), HTTP/S scanning, and exploit deployment. Victims have been found communicating with a Russian crypto-mining service called Kryptex. Once compromised, servers become springboards for further spreading the malware, using scanning on ports 3000 and 4000 associated with Gotenberg and LiteLLM.
Notably, BLL researchers found that several C2 servers featured vulnerable router administration interfaces, suggesting that the attacker reused compromised routers in the attacks. While attribution is uncertain, they assess with moderate confidence that the operator may be Italian based on comments in the malware and an Italy-based server hosting the administrative interface.
To protect against PoeLLM attacks, system administrators should prioritize applying the latest security updates, reducing public internet exposure for critical assets, and restricting external access to trusted IPs. Regularly inspecting network monitoring logs for connections to indicators of compromise (IoCs) shared by Black Lotus Labs is also crucial.
As AI-powered services become increasingly exposed online, threat actors are finding innovative ways to exploit them. This campaign serves as a stark reminder of the need for robust security measures and ongoing vigilance in protecting against emerging threats.
Source: Bleeping Computer — 2026-10-07