PoeLLM malware infects exposed AI servers in cryptomining attacks
PoeLLM malware targets exposed AI servers, using a poem for C2 addresses. Researchers found 3,400 compromised servers, with activity peaking at 800 infected systems.
Intelligence analysis by Qwen 2.5 (3B)

PoeLLM malware exploits exposed AI servers for cryptomining. Researchers discovered 3,400 compromised servers, with activity peaking at 800 infected systems.
A bad computer program called PoeLLM is using a poem to trick servers into doing bad things. It's like a game of hide and seek, but with computers. The servers are used to do bad things like make money by using a lot of computer power.
Analysis
{"heading_1":"PoeLLM Malware Overview","paragraph_1":"System administrators should apply the latest security updates, reduce public internet exposure for critical assets, and restrict external access only to trusted IPs.","paragraph_2":"Administrators are recommended to inspect network monitoring logs and look for connections to the indicators of compromise (IoCs) shared by Black Lotus Labs.","paragraph_3":"The PoeLLM attack uses scanning on ports 3000 and 4000, associated with Gotenberg and LiteLLM, and attempts to exploit CVE-2026-42271 and CVE-2026-48710.","heading_2":"Infrastructure and Attack Methods","heading_3":"Mitigation and Prevention"}
Key points
- PoeLLM malware targets exposed AI servers for cryptomining
- Researchers found 3,400 compromised servers, with activity peaking at 800 infected systems
- The malware uses a poem for C2 address construction
- The operator is assessed with moderate confidence to be Italian
- System administrators should apply the latest security updates and monitor for suspicious activity
By improving security practices and monitoring for suspicious activity, we can prevent PoeLLM and similar attacks from happening.
If PoeLLM continues to evolve, it could become more difficult to detect and stop, leading to more damage and loss of data.


