Trusence Every claim has a source
Last updated 7 October 2026 Search Türkçe
← All stories
Security

PoeLLM botnet hits more than 2,100 exposed AI servers in mining campaign

The infections show internet-facing AI and related tools can be turned into mining hosts and traffic relays at scale.

Researchers say the PoeLLM cryptomining botnet has infected more than 2,100 exposed AI and related servers, with some 800 systems active in a single day, and it matters because the campaign turns cloud and GPU-heavy infrastructure into scanners, exploit relays, and mining hosts. Black Lotus Labs says the malware has been active since at least April and has used at least 11 command-and-control servers, with victims concentrated in the United States and Western Europe. The infections often hit publicly reachable tools such as LiteLLM, Ollama, Gotenberg, and Gitea, and the operators appear to be chaining compromise into further spread by scanning ports 3000 and 4000 and trying to exploit CVE-2026-42271. PoeLLM also hides its C2 addresses by pulling words from a poem hosted in a GitHub file, and analysts say it has been linked to traffic toward the Kryptex mining service. Black Lotus Labs could not firmly attribute the campaign, but says it has moderate confidence the operator is Italian based on malware comments and an Italy-hosted admin interface.

Why it matters

The campaign affects operators of exposed AI and developer-facing services across the United States and Western Europe, especially those running tools such as LiteLLM, Ollama, Gotenberg, and Gitea. It shows that once these systems are reachable from the internet, they can be folded into a wider botnet and pushed into mining activity, not just used as a single point of compromise. That raises the stakes for anyone running public AI infrastructure and for the services those machines expose.

Sources

  • BleepingComputer