PoeLLM malware uses GitHub poem to control cryptomining botnet on 3,400 AI servers
Black Lotus Labs reports that a malware strain called PoeLLM has compromised more than 3,400 exposed AI servers, with up to 800 infected systems active on a single day. The malware, an ELF file named libgcrypt, derives its command-and-control IP address by extracting keywords from a poem hosted in a GitHub repository, updating the poem 11 times since April to rotate C2 addresses.
GoKawiil's interpretation of the reporting above, not reported fact.
The targeting of exposed AI tools like LiteLLM and Ollama suggests attackers see poorly secured AI infrastructure as a prime target, since such systems often run on powerful GPUs well-suited for cryptomining. The poem-based C2 scheme could make detection and blocking harder for defenders, as researchers say they suspect further updates to the technique may follow.
- PoeLLM malware has infected over 3,400 servers, with up to 800 active in a single day.
- The malware derives C2 addresses by mapping keywords from a GitHub-hosted poem to IP numbers.
- Compromised AI tools include LiteLLM, Ollama, Gotenberg, Gitea, and possibly Ivanti Sentry.
YubiKey 5C NFC Security Key — Exposed servers and weak access controls are exactly how botnets like PoeLLM get a foothold. Hardware security keys like the YubiKey add strong, phishing-resistant authentication for admin accounts protecting servers and cloud consoles, making unauthorized access much harder for attackers.A small step that meaningfully raises the bar against opportunistic infrastructure attacks.
See YubiKey 5C NFC Security Key on Amazon → Affiliate link — we may earn a commission on purchases, at no extra cost to you. Product picked by AI based on this article; it is not a tested recommendation.Source: bleepingcomputer.com, 2026-10-07
Published there as: “PoeLLM malware infects exposed AI servers in cryptomining attacks”
Read the original report → The summary and analysis above are GoKawiil's own, written from reporting by the source above. Facts and quotes belong to the original publisher.