Find notable cyber news and cases, enriched with sources, timelines, and signals.

PoeLLM cryptomining and scanning malware activity against exposed AI servers

Malware Activity
First reported
Last updated
Happening score
H score 58
1 unique sources, 1 articles

Summary

Hide ▲

The PoeLLM malware is compromising exposed AI servers and turning them into cryptomining, scanning, and exploit-launch platforms, with more than 2,100 servers already affected. Activity spans the United States and Western Europe and has been active since at least April. The malware’s operator also uses a GitHub-hosted poem to hide command-and-control discovery and keep the infrastructure shifting.

Related Happenings

PoeLLM cryptomining campaign targeting exposed AI services

Campaign
H score67 First: 07.10.2026 18:04 Last: 07.10.2026 18:04 Sources 1

How related: A cryptomining campaign targeting exposed AI services is using PoeLLM malware to turn compromised servers into scanners and exploit launchpads.

About this happening: The PoeLLM campaign is abusing exposed AI services to turn compromised servers into scanners and exploit launchpads, expanding risk across the United States and West...

Transparent Tribe Operation RapidRust campaign targeting India and Afghanistan

Campaign
H score38 First: 18.09.2026 18:24 Last: 18.09.2026 18:24 Sources 1

About this happening: The Transparent Tribe operation Operation RapidRust is sustaining active cyber attacks against government and defense organizations in India and Afghanistan, raising t...

Widespread exposure and misconfiguration in self-hosted AI infrastructure

Trend
H score76 First: 05.05.2026 13:30 Last: 05.05.2026 13:30 Sources 1

About this happening: A large-scale measurement found self-hosted AI infrastructure was being deployed with widespread exposure and no authentication, creating a broad risk of data theft, workf...

Famous Chollima PromptMink supply-chain campaign targeting Web3 developers

Campaign
H score44 First: 29.04.2026 17:43 Last: 29.04.2026 17:43 Sources 1

About this happening: The PromptMink campaign is widening Famous Chollima's supply-chain intrusion playbook by pushing tainted npm packages into developer environments and stealing secrets....

Atomic MacOS Stealer (AMOS) distribution through AI-app lures, SEO poisoning, and supply-chain abuse

Malware Activity
H score31 First: 12.02.2026 16:25 Last: 12.02.2026 16:25 Sources 1

About this happening: Atomic MacOS Stealer (AMOS) is being distributed to macOS users through AI platform trust abuse, including Claude Artifacts, claude.ai/share links, and shared...

Timeline

  1. 07.10.2026 18:04 2 articles · 1h ago

    PoeLLM malware turns exposed AI servers into cryptomining and exploit nodes

    Initial Disclosure

    Black Lotus Labs describes PoeLLM, an ELF file named libgcrypt, as targeting exposed AI services and turning compromised servers into scanners and exploit launchpads. The campaign has compromised more than 2,100 servers, with peak activity reaching 800 infected systems in a single day, and victims have been observed across the United States and Western Europe. PoeLLM retrieves command-and-control addresses from keywords in a poem hosted in GitHub, uses XMRig and Iron miners, performs HTTP/S scanning, deploys exploits, and has been linked to Kryptex; exposed targets include LiteLLM, Ollama, Gotenberg, Gitea, and Ivanti Sentry, with attempted exploitation of CVE-2026-42271 and a chained path with CVE-2026-48710.

    Show sources