PoeLLM Malware Compromises 3,400+ AI Servers for Cryptomining
Article Content
- •PoeLLM malware has infected over 3,400 servers since April 2026.
- •The malware derives C2 addresses from a poem on GitHub, allowing stealthy operations.
- •It targets exposed AI services, deploying cryptocurrency miners and expanding its botnet.
PoeLLM malware has targeted exposed AI services since April 2026, compromising over 3,400 servers. The malware uses a unique method to derive command-and-control (C2) server addresses from a poem hosted on GitHub. It has been linked to a cryptomining campaign, deploying miners like XMRig and Iron, and connecting victims to the Kryptex mining service. The attacks primarily affect systems running LiteLLM, Ollama, Gotenberg, and Gitea, with significant activity observed in the U.S. and Western Europe. The malware's functionality allows it to turn compromised servers into scanners and exploit launchpads for further attacks. Notable CVEs associated with the exploited vulnerabilities include CVE-2026-42271 and CVE-2026-48710. The campaign has shown a significant increase in activity, with peak infections reaching 800 active systems in a single day. Researchers attribute the operation to an Italian-speaking threat actor, based on language artifacts found in the malware.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (4)
Following this threat?
Track PoeLLM, Black Lotus Labs and CVE-2026-42271 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
Which systems are affected by PoeLLM?
What should organizations do to protect against PoeLLM?
Is there evidence of active exploitation of vulnerabilities?
Continue Reading
Critical Citrix NetScaler Vulnerabilities Actively Exploited in Finland The National Cyber Security Centre Finland (NCSC-FI) issued an alert regarding critical vulnerabilities in Citrix NetScaler ADC and Gateway products, specifically CVE-2026-88771 and CVE-2026-88772, which are being actively exploited in Finland. These vulnerabilities allow attackers to execute remote code without…
Critical Citrix NetScaler Zero-Day Vulnerabilities Exploited In late September 2026, two critical zero-day vulnerabilities (CVE-2026-88771 and CVE-2026-88772) in Citrix NetScaler ADC and Gateway were actively exploited, allowing remote code execution. The Cybersecurity and Infrastructure Security Agency (CISA) added these CVEs to its Known Exploited Vulnerabilities catalog on…