Find notable cyber news and cases, enriched with sources, timelines, and signals.

PoeLLM cryptomining campaign targeting exposed AI services

Campaign
First reported
Last updated
Happening score
H score 67
1 unique sources, 1 articles

Summary

Hide ▲

The PoeLLM campaign is abusing exposed AI services to turn compromised servers into scanners and exploit launchpads, expanding risk across the United States and Western Europe. It has compromised more than 2,100 servers and reached as many as 800 infected systems in a single day. Activity has been underway since at least April, and the infrastructure now relies on a GitHub-hosted poem to derive changing C2 addresses.

Related Happenings

PoeLLM cryptomining and scanning malware activity against exposed AI servers

Malware Activity
H score58 First: 07.10.2026 18:04 Last: 07.10.2026 18:04 Sources 1

How related: The malware incorporates remote-shell functionality, XMRig and Iron cryptocurrency miners, HTTP/S scanning, and exploit deployment capabilities.

About this happening: The PoeLLM malware is compromising exposed AI servers and turning them into cryptomining, scanning, and exploit-launch platforms, with more than 2,100 servers alre...

Vo1d botnet campaign targeting unofficial Android-based TV boxes

Campaign
H score88 First: 18.06.2026 20:37 Last: 18.06.2026 20:37 Sources 1

About this happening: NetNut used the Popa botnet and deceptive SDKs on off-brand Android-based smart TVs, streaming media boxes, and unofficial apps to turn home connections into residen...

Latest development: 03.07.2026 12:35

Google disabled all Google accounts used by NetNut for malware command-and-control, updated Google Play Protect to warn Android users, and disabled apps containing the compromised SDKs. The FBI’s seizure banner appeared on netnut.com while netnut.io briefly remained accessible, and Google said the coordinated actions caused significant degradation to NetNut’s proxy network and business operations.

Calypso telecommunications espionage campaign using Showboat and JFMBackdoor

Campaign
H score36 First: 21.05.2026 17:00 Last: 21.05.2026 17:00 Sources 1

About this happening: A Calypso / Red Lamassu espionage campaign is targeting telecommunications providers with new Showboat and JFMBackdoor malware, increasing the risk of long-term co...

Widespread exposure and misconfiguration in self-hosted AI infrastructure

Trend
H score76 First: 05.05.2026 13:30 Last: 05.05.2026 13:30 Sources 1

About this happening: A large-scale measurement found self-hosted AI infrastructure was being deployed with widespread exposure and no authentication, creating a broad risk of data theft, workf...

Bluekit alliance reshapes ransomware ecosystem operations

Threat Actor Meta
H score25 First: 30.04.2026 21:58 Last: 30.04.2026 21:58 Sources 1

About this happening: BlueKit is a phishing-as-a-service offering that has expanded from AI-assisted campaign drafting into browser-in-the-middle (BitM) login theft. The kit initially o...

Latest development: 25.06.2026 18:00

Bluekit phishing-as-a-service added browser-in-the-middle (BitM) login theft and nearly 70 new hostnames over the past week. Netcraft said the kit now uses the open-source JavaScript library rrweb to serialize the page DOM and stream it over a WebSocket connection, while the live 5-second monitoring system and victim qualification checks remain in use.

Timeline

  1. 07.10.2026 18:04 2 articles · 1h ago

    PoeLLM campaign compromises more than 2,100 exposed AI servers

    Initial Disclosure

    Black Lotus Labs says PoeLLM cryptomining malware has compromised more than 2,100 exposed AI servers across the United States and Western Europe, with peak activity reaching 800 infected systems in a single day. The malware uses an ELF file named libgcrypt to derive command-and-control addresses from a poem in a GitHub-hosted dash.css file, then reuses compromised servers for remote-shell access, XMRig and Iron mining, HTTP/S scanning, and exploit attempts against LiteLLM MCP server test endpoints via CVE-2026-42271, which Horizon.ai researchers say can be chained with CVE-2026-48710 for unauthenticated RCE. Victims include exposed LiteLLM, Ollama, Gotenberg, and Gitea deployments, signs of Ivanti Sentry targeting were also found, and BLL observed victim communications with Kryptex; the operator is assessed with moderate confidence to be Italian.

    Show sources