bleeping-computer · Crawled Oct 7, 2026

PoeLLM malware infects exposed AI servers in cryptomining attacks

3 IoCs 2 CVEs
Read original article ↗

AI Summary

The PoeLLM malware is a cryptomining campaign targeting exposed AI servers, particularly those running LiteLLM, Ollama, Gotenberg, and Gitea. It uses an ELF file named libgcrypt that retrieves command-and-control (C2) addresses by extracting keywords from a poem hosted on GitHub, which are then mapped to IPv4 addresses via a hardcoded dictionary. The malware enables remote shell access, deploys XMRig and Iron cryptocurrency miners, and turns infected servers into scanners to propagate further, exploiting CVE-2026-42271 and potentially chaining it with CVE-2026-48710 for unauthenticated RCE. Over 3,400 servers have been compromised, primarily in the US and Western Europe, with C2 infrastructure showing signs of Italian origin.

AI-extracted · verify before operational use

Extracted Entities 2 found

Indicators of Compromise 3 extracted

Type Value Detail
Filename libgcrypt Details →
GitHub Repo dash.css Details →
Domain kryptex[.]com Details →

MITRE ATT&CK TTPs 19 techniques