PoeLLM malware infects exposed AI servers in cryptomining attacks
AI Summary
The PoeLLM malware is a cryptomining campaign targeting exposed AI servers, particularly those running LiteLLM, Ollama, Gotenberg, and Gitea. It uses an ELF file named libgcrypt that retrieves command-and-control (C2) addresses by extracting keywords from a poem hosted on GitHub, which are then mapped to IPv4 addresses via a hardcoded dictionary. The malware enables remote shell access, deploys XMRig and Iron cryptocurrency miners, and turns infected servers into scanners to propagate further, exploiting CVE-2026-42271 and potentially chaining it with CVE-2026-48710 for unauthenticated RCE. Over 3,400 servers have been compromised, primarily in the US and Western Europe, with C2 infrastructure showing signs of Italian origin.
AI-extracted · verify before operational use