PoeLLM targets exposed AI servers for cryptomining
Black Lotus Labs says PoeLLM has affected more than 3,400 servers, targeting internet-facing AI services and other applications in a campaign that combines cryptocurrency mining with exploit scanning.

Key takeaways · 4
- 01
Review internet exposure for LiteLLM, Ollama, Gotenberg and Gitea services.
- 02
Apply current security updates and restrict external access to trusted IPs, as Black Lotus Labs recommends.
- 03
Do not treat the reported LiteLLM vulnerability as proof it was used in this campaign; the evidence only says it affects MCP server test endpoints.
- 04
Account for compromised servers being used to scan and exploit other systems.
A campaign targeting exposed services
Black Lotus Labs describes PoeLLM as a cryptocurrency-mining and exploit-scanning campaign aimed at enterprise AI infrastructure and other applications.[1] It says the malware primarily targets vulnerable, internet-facing LiteLLM and Ollama services, as well as Gotenberg and Gitea; Ivanti Sentry may also have been targeted.[1] The campaign has impacted more than 3,400 victim servers, and its peak activity exceeded 800 active servers per day, according to Black Lotus Labs.[1] Victims are predominantly in the United States and Western Europe.[1]
Mining and scanning capabilities
PoeLLM includes remote-shell functionality, XMRig and Iron cryptocurrency miners, HTTP/S scanning, and exploit deployment, Black Lotus Labs says.[1] The organization also says the malware connects victims to Kryptex, a Russian crypto-mining service.[2] Compromised servers are used as scanning and exploitation workers to help expand the botnet.[1] That means an infected server may play a role beyond mining: it can also help the campaign find and exploit additional systems.[1]
A poem directs command and control
Black Lotus Labs says PoeLLM derives the address of its command-and-control server from keywords in a poem hosted in a GitHub repository.[1] The poem, “On the Nature of Connection,” is stored in a file named “dash.css”; four words are matched to numbers and combined to form an IPv4 address.[1] The poem had been changed 11 times, with each iteration pointing infected systems to a new C2 server, according to Black Lotus Labs.[1] The threat actor’s first commit to the repository was on April 13, 2026.[1]
Response and attribution limits
Lumen says Black Lotus Labs blocked traffic to and from PoeLLM’s C2 servers and will continue monitoring for new traffic.[1] Lumen also says its Defender customers have been protected from PoeLLM servers since the malware was discovered.[1] Black Lotus Labs recommends applying current security updates, limiting public internet exposure for critical assets, and restricting external access to trusted IPs.[2] It could not confidently attribute the campaign to an operator.[2] Separately, CVE-2026-42271 impacts LiteLLM’s MCP server test endpoints; the evidence does not establish that PoeLLM exploited it.[2]
Teams responsible for AI infrastructure should treat internet exposure and patching as operational priorities, particularly for the named services. PoeLLM’s reported use of compromised servers for scanning and exploitation also makes containment relevant to the security of systems beyond the initial victim.
Why it matters
Test yourself on this story — 1 question.
Create a free account to take the quiz, earn XP, and get a daily session built for your industry.
Take the quizHow this developed
9 October 2026
PoeLLM targets exposed AI servers for cryptomining