Cryptomining botnet PoeLLM targets AI infrastructure servers, researchers warn
A cryptomining botnet called PoeLLM is targeting servers running popular AI and development services, according to Lumen's Black Lotus Labs. The malware uses a poem on GitHub to coordinate its command-and-control infrastructure by translating words into IP addresses. Researchers identified compromised deployments running LiteLLM, Ollama, Gotenberg, and Gitea, with activity traced back to April 2026. The botnet uses infected hosts to mine cryptocurrency and scan for additional victims. Security researchers advise administrators of these services to verify their network configurations and update vulnerable software.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)
Log in to join the discussion and vote.
Log in