PoeLLM Malware Targets Exposed AI Servers in Cryptomining Campaign

Summary
PoeLLM has compromised more than 3,400 exposed servers, using an unusual poem-based method to retrieve C2 addresses and turning infected systems into cryptomining hosts, scanners, and exploit launchpads.
Key points
- Black Lotus Labs reports more than 3,400 compromised servers, with up to 800 active in a single day; victims were mainly in the United States and Western Europe.
- Targets included exposed LiteLLM and Ollama services, Gotenberg, and Gitea; researchers also found signs of Ivanti Sentry targeting.
- The ELF malware derives an IPv4 command-and-control address from words in a poem hosted in a GitHub repository, allowing operators to change the address by editing the poem.
- PoeLLM includes remote-shell access, XMRig and Iron miners, web scanning, and exploit-deployment capabilities; infected servers are used to spread the malware.
- The campaign scans ports associated with Gotenberg and LiteLLM and attempts to exploit CVE-2026-42271. Researchers say it can be chained with CVE-2026-48710 for unauthenticated remote code execution.
- Black Lotus Labs could not confidently attribute the operation, but assessed with moderate confidence that the operator is Italian.
- Recommended defenses include applying security updates, limiting public exposure and access to trusted IPs, and checking network logs for the published indicators of compromise.
Article Details
- Attack Vectors
- PoeLLM targets exposed servers running AI tools and other services, including LiteLLM, Ollama, Gotenberg, and Gitea; researchers also found signs of Ivanti Sentry targeting.
- Compromised servers scan ports 3000 and 4000, associated with Gotenberg and LiteLLM, and attempt to exploit CVE-2026-42271 to spread the malware.
- PoeLLM derives a C2 IPv4 address from words or phrases in a poem hosted in a GitHub repository. Researchers report that the operator has changed the poem 11 times.
- PoeLLM includes remote-shell, cryptocurrency-mining, HTTP/S-scanning, and exploit-deployment capabilities.
- Horizon.ai researchers confirmed that CVE-2026-42271 can be chained with CVE-2026-48710 for unauthenticated remote code execution; the article does not establish that PoeLLM uses this chain.
- Defensive Notes
- Apply the latest security updates, reduce public internet exposure of critical assets, and restrict external access to trusted IPs.
- Inspect network-monitoring logs for connections to the indicators shared by Black Lotus Labs.
MITRE ATT&CK
T1102.001 · Dead Drop ResolverPoeLLM retrieves words from a poem hosted on GitHub and converts them into its C2 IPv4 address.T1190 · Exploit Public-Facing ApplicationCompromised servers attempt to spread PoeLLM by exploiting CVE-2026-42271 in exposed LiteLLM endpoints.T1496 · Resource HijackingPoeLLM uses compromised servers for cryptocurrency mining with XMRig and Iron miners.T1595 · Active ScanningPoeLLM-infected servers scan ports 3000 and 4000 while seeking systems on which to spread.
CVE
CVE-2026-42271Once a server is compromised, it becomes a springboard to spread the malware further, using scanning on ports 3000 and 4000, associated with Gotenberg and LiteLLM, and attempting to exploit CVE-2026-42271.CVE-2026-48710Horizon.ai researchers confirmed that it could be chained with another security issue, CVE-2026-48710, for unauthenticated remote code execution (RCE).
Malware
Vendors
Products
GiteaMany of those victims run exposed AI tools such as LiteLLM and Ollama, the Gotenberg PDF converter, and the Gitea development toolkit, while signs of Ivanti Sentry targeting were also uncovered.GotenbergMany of those victims run exposed AI tools such as LiteLLM and Ollama, the Gotenberg PDF converter, and the Gitea development toolkit, while signs of Ivanti Sentry targeting were also uncovered.Ivanti SentryMany of those victims run exposed AI tools such as LiteLLM and Ollama, the Gotenberg PDF converter, and the Gitea development toolkit, while signs of Ivanti Sentry targeting were also uncovered.LiteLLMMany of those victims run exposed AI tools such as LiteLLM and Ollama, the Gotenberg PDF converter, and the Gitea development toolkit, while signs of Ivanti Sentry targeting were also uncovered.OllamaMany of those victims run exposed AI tools such as LiteLLM and Ollama, the Gotenberg PDF converter, and the Gitea development toolkit, while signs of Ivanti Sentry targeting were also uncovered.
Tools
Countries
ItalyThe researchers could not make a confident attribution but assess with moderate confidence that the operator is Italian, based on comments in the malware and an Italy-based server hosting the administrative interface.United StatesAccording to the research, the operation targeted systems across the United States and Western Europe.