PoeLLM malware builds botnet targeting AI services
Researchers have identified malware named PoeLLM that has compromised over 3,400 servers since April by targeting open-source AI services. The malware uses words hidden in a seemingly harmless poem on GitHub to generate command-and-control server addresses, making it harder to detect and disrupt. PoeLLM mainly exploits vulnerabilities to build a cryptocurrency-mining botnet but could allow remote code execution on affected servers, posing further risks.
- PoeLLM compromised over 3,400 servers since April
- Uses poem on GitHub to hide C2 infrastructure
- Targets open-source AI services like LiteLLM and Ollama
- Botnet used for exploit scanning and crypto mining
- Malware enables remote code execution on some servers
Sources covering this
In this story
More in Cybersecurity
Four states sue TP-Link over router security claims
Florida and three other US states have filed lawsuits against TP-Link, alleging the company misled consumers about its routers' security…
Outlook will block MSIX file attachments in November
Microsoft will begin blocking .msix and .msixbundle attachments in Outlook on the web and the new Outlook for Windows starting in November.
Major software vendors patch critical vulnerabilities
Cisco Talos researchers reported multiple vulnerabilities in products from Microsoft, Adobe, Apple, and Foxit.
PoeLLM malware infects over 3,400 AI servers for cryptomining
A new malware called PoeLLM has compromised more than 3,400 servers running exposed artificial intelligence and large language model…