Threat

PoeLLM malware infects exposed AI servers in cryptomining attacks

Page published · Page updated

Dossier

Earliest dated coverage: 7 Oct 2026 · First observed: 7 Oct 2026 · Latest dated coverage: 7 Oct 2026

Coverage timeline

7 Oct 2026bleepingcomputer.com

Single-source incident — one report is available.

Why it matters

PoeLLM demonstrates that exposed, poorly configured LLM infrastructure on powerful GPU clusters is now being actively weaponized at scale, exploiting MCP server endpoints for self-propagating cryptomining attacks.

PoeLLM malware, tracked by Lumen's Black Lotus Labs, has compromised more than 2,100 exposed AI servers running tools like LiteLLM and Ollama, turning them into cryptomining nodes and exploit launchpads. The malware uses an unusual C2 retrieval method that extracts keywords from a GitHub-hosted poem to generate IPv4 addresses, and spreads by exploiting CVE-2026-42271 in LiteLLM's MCP server test endpoints, chained with CVE-2026-48710 for unauthenticated RCE.

campaign

Summary

Lumen's Black Lotus Labs has detailed PoeLLM, a cryptomining campaign that turns compromised, internet-exposed AI servers into scanners and exploit launchpads. The operation has compromised more than 2,100 servers, with peak activity of as many as 800 infected systems active on a single day, concentrating on victims across the United States and Western Europe.[1]

The malware is notable for an uncommon C2-resolution technique: it extracts four words or phrases from a poem titled 'On the Nature of Connection' hosted in a GitHub repository and maps them to numbers via a hard-coded dictionary to derive the C2 IPv4 address. Operators rotate C2 by editing the poem, which has already been changed 11 times.[1]

PoeLLM targets poorly configured AI/LLM deployments such as LiteLLM and Ollama, alongside Gotenberg, Gitea, and Ivanti Sentry, because these systems are frequently exposed and run on powerful GPUs suited to cryptomining. Infected hosts spread the malware by scanning ports 3000 and 4000 and exploiting CVE-2026-42271 in LiteLLM.[1]

Attack chain

  1. Initial access: The malware targets internet-exposed AI/LLM services (LiteLLM, Ollama), Gotenberg PDF converter, Gitea, and Ivanti Sentry, exploiting poorly configured deployments; infected hosts attempt to exploit CVE-2026-42271 in LiteLLM's MCP server test endpoints.[1]
  2. C2 resolution: PoeLLM (ELF named libgcrypt) retrieves four words/phrases from a poem titled 'On the Nature of Connection' in a dash.css file in a GitHub repo forking Node.js, mapping the words to numbers with a hard-coded dictionary to construct the C2 IPv4 address.[1]
  3. Execution / monetization: The malware deploys XMRig and Iron cryptocurrency miners and uses remote-shell functionality, with victims communicating with the Russian crypto-mining service Kryptex.[1]
  4. Propagation: Each compromised server becomes a springboard, performing HTTP/S scanning on ports 3000 and 4000 and attempting exploitation to spread PoeLLM further.[1]

Disclosure timeline

DateEvent
April 2026PoeLLM activity first observed, with campaign activity increasing significantly thereafter.[1]
October 7, 2026Black Lotus Labs publishes its report on PoeLLM; BleepingComputer reports the campaign.[1]

Actor profile

PoeLLM operator (unattributed)

Black Lotus Labs could not make a confident attribution but assesses with moderate confidence that the operator is Italian, based on comments in the malware and an Italy-based server hosting the administrative interface. Analysis also found several C2 servers with vulnerable router administration interfaces, suggesting the attacker reused compromised routers in the campaign.[1]

How it works

CVE-2026-42271 impacts LiteLLM's MCP server test endpoints and was originally disclosed as requiring authentication with a high-severity score. Horizon3.ai researchers confirmed it can be chained with CVE-2026-48710 to achieve unauthenticated remote code execution.[1][2]

Affected versions and patch status

ProductAffectedPatch status
LiteLLMMCP server test endpoints affected by CVE-2026-42271 (chainable with CVE-2026-48710 for unauthenticated RCE)Not specified in evidence; administrators advised to apply latest security updates[1]
Ollama, Gotenberg PDF converter, Gitea, Ivanti SentryExposed instances observed as PoeLLM targets/victimsNot specified in evidence[1]

Indicators of Compromise

TypeIndicatorContext
cveCVE-2026-42271LiteLLM MCP server test endpoint vulnerability that infected PoeLLM hosts attempt to exploit for propagation.[1]
cveCVE-2026-48710Secondary vulnerability chained with CVE-2026-42271 to achieve unauthenticated remote code execution.[1]
file-pathlibgcryptFilename used by the PoeLLM ELF malware binary.[1]
otherdash.css containing poem 'On the Nature of Connection'GitHub-hosted file (in a repo forking Node.js) from which the malware derives its C2 IPv4 address via a hard-coded word-to-number dictionary.[1]
otherTCP ports 3000 and 4000Ports scanned by infected hosts, associated with Gotenberg and LiteLLM, during self-propagation.[1]
otherKryptexRussian crypto-mining service that PoeLLM victims communicate with.[1]

Key takeaways

  • Exposed AI/LLM services are attractive cryptomining targets because they are often misconfigured and run on powerful GPUs.[1]
  • PoeLLM's poem-based C2 resolution lets operators rotate C2 addresses simply by editing a GitHub-hosted poem, complicating static blocking.[1]

Defensive actions

  • Apply the latest security updates to exposed AI/LLM and supporting services.: PoeLLM exploits poorly configured and unpatched deployments, including CVE-2026-42271 in LiteLLM.[1]
  • Reduce public internet exposure for critical assets and restrict external access to trusted IPs.: The campaign specifically targets internet-exposed AI tools running on powerful GPU clusters.[1]
  • Inspect network monitoring logs for connections to the IoCs shared by Black Lotus Labs, including scanning on ports 3000 and 4000.: Infected hosts scan and exploit to propagate, and connect to attacker C2 and mining infrastructure.[1]