ProBackend
exposed ai model endpoints compute hijacking
just now4 min read

PoeLLM and AI Driven Endpoint Security Trends Nobody Planned For

Lumen Black Lotus Labs discovered PoeLLM, a malware campaign compromising over 3,400 exposed AI servers for cryptomining and exploit propagation using GitHub-hosted poetry for C2.

The Botnet That Reads Poetry

Command-and-control infrastructure is usually a compromised virtual private server tucked away in an unmonitored hosting provider or hidden behind layers of bulletproof proxies. But the threat actors behind PoeLLM decided on something far more literary. This malware pulls its command-and-control IP address by parsing specific keywords out of a poem hosted publicly on GitHub.

Discovered by researchers at Lumen’s Black Lotus Labs, PoeLLM has quietly infected more than 3,400 exposed servers across the United States and Western Europe. What starts as a quiet intrusion for cryptomining quickly morphs into something much more dangerous: compromised nodes are weaponized as network scanners and automated exploit launchpads, targeting other vulnerable enterprise environments.

Poetry, Git, and Dynamic C2 Resolution

Operating under the unassuming guise of an ELF binary named libgcrypt, PoeLLM employs an unusual obfuscation tactic for its infrastructure. Rather than hardcoding IP addresses or relying on domain generation algorithms (DGAs), the malware connects to GitHub and reads a file named dash.css inside a repository that mimics a Node.js fork.

Inside that CSS file lies a poem titled “On the Nature of Connection.” The malware extracts four specific words or phrases from the text and runs them through a hard-coded dictionary mapping to reconstruct a valid IPv4 address for its C2 server.

When the operators want to rotate their infrastructure, they do not spin up a brand new domain or register a fresh registrar account—they simply edit the poem. Researchers have tracked at least 11 updates to the poem since April, demonstrating a persistent effort to dodge static blocklists and traditional perimeter defenses.

Why Exposed AI Services Make Prime Targets

The rapid proliferation of AI and large language model tooling has fundamentally altered enterprise attack surfaces. Developers often spin up powerful frameworks like LiteLLM, Ollama, Gotenberg, and Gitea on high-performance infrastructure without enforcing strict network boundaries or authentication layers.

For threat actors, these deployments represent an ideal intersection of heavy computing power and lax configuration. High-end GPU clusters and well-resourced server instances running AI endpoints are custom-built for high-yield cryptocurrency mining.

This campaign highlights a stark reality within modern ai driven endpoint security trends: securing the traditional operating system layer is no longer sufficient when specialized AI services run with root-level privileges and direct exposure to the public internet. Organizations are discovering that convenience often trumps hardening during rapid AI prototyping.

From Miners to Exploit Launchpads

While initial telemetry indicated that PoeLLM was primarily dropping XMRig and Iron miners to siphon resources for Kryptex—a Russian cryptocurrency mining service—the malware's capabilities extend far beyond passive resource theft. Once a server is successfully breached, the infection routine installs full remote-shell functionality and initiates aggressive reconnaissance across the local network.

Compromised systems immediately start scanning external ports 3000 and 4000, which are commonly associated with Gotenberg and LiteLLM services. The malware uses these discovery scans to identify neighboring vulnerable instances and automatically deploy exploits, most notably targeting CVE-2026-42271.

While CVE-2026-42271 originally carried a high-severity score and assumed authenticated access, security researchers confirmed it can be chained seamlessly with CVE-2026-48710 to achieve unauthenticated remote code execution. By turning infected AI servers into automated exploit launchpads, the botnet scales its footprint autonomously across enterprise boundaries. The self-propagating hunt for the next vulnerable host is not new in spirit: what attackers do after gaining initial access follows a similar playbook of enumeration and lateral tooling, only here it is fully automated and aimed at AI infrastructure.

Attribution Clues and Infrastructure Reuse

Pinpointing the exact origin of a sophisticated threat actor is notoriously difficult, but Black Lotus Labs uncovered interesting breadcrumbs during their infrastructure analysis. Comment strings embedded within the malware alongside the geographic hosting location of an administrative interface in Italy point with moderate confidence toward an Italian-speaking operator.

Curiously, several of the C2 servers utilized by the botnet featured vulnerable router administration interfaces, suggesting that the operators engaged in slipshod operational security by reusing compromised consumer or enterprise routers to manage their own infrastructure.

Defending GPU Infrastructure and AI Workloads

Mitigating threats like PoeLLM requires moving beyond standard endpoint protection and establishing rigorous security baselines around AI deployment environments. Even the most advanced detection stacks have known gaps—process parameter poisoning and the blind spots in AI-driven endpoint security shows how malware can disguise its command line from modern telemetry, a technique that complements PoeLLM's living-off-the-land C2 trickery. Security teams should prioritize several foundational controls:

  • Restrict Public Exposure: Isolate internal AI models, LLM gateways, and development tools behind private Virtual Private Networks (VPNs) or zero-trust access gateways rather than exposing them directly to the public internet.
  • Enforce Strict Authentication: Ensure all management dashboards, MCP servers, and API endpoints require robust authentication and token validation, mitigating vulnerabilities like CVE-2026-42271.
  • Continuous Log Monitoring: Inspect network telemetry for outbound connections to known indicators of compromise and monitor for anomalous port scanning activity targeting ports 3000 and 4000.
  • Patch Management: Rapidly apply vendor patches for AI frameworks, container runtimes, and auxiliary development utilities as soon as updates become available.

As adversaries continue to weaponize specialized enterprise infrastructure, closing the gap between AI innovation and foundational security posture remains the most effective defense against automated botnets. The same theme of sandbox and agent boundary escapes recurs across this year's AI-driven threats: every new layer of AI convenience becomes a new place an attacker can stand.

the botnet that reads poetry

More blogs