PoeLLM malware infects over 3,400 AI servers for cryptomining
A new malware called PoeLLM has compromised more than 3,400 servers running exposed artificial intelligence and large language model (LLM) services. The malware turns affected servers into scanning and exploitation tools, and installs cryptocurrency miners, connecting them to a Russian service to profit. PoeLLM uses an unusual technique to hide its command-and-control addresses within a poem on GitHub, changing the poem to update locations. Most targets are based in the US and Western Europe.
- Over 3,400 servers have been compromised
- Targets include LiteLLM, Ollama, Gotenberg, Gitea
- Malware uses a poem on GitHub to guide attacks
- Servers are used for cryptomining and spreading malware
- Most victims are in the US and Western Europe
Sources covering this
In this story
More in Cybersecurity
Four states sue TP-Link over router security claims
Florida and three other US states have filed lawsuits against TP-Link, alleging the company misled consumers about its routers' security…
Outlook will block MSIX file attachments in November
Microsoft will begin blocking .msix and .msixbundle attachments in Outlook on the web and the new Outlook for Windows starting in November.
Major software vendors patch critical vulnerabilities
Cisco Talos researchers reported multiple vulnerabilities in products from Microsoft, Adobe, Apple, and Foxit.
PoeLLM malware builds botnet targeting AI services
Researchers have identified malware named PoeLLM that has compromised over 3,400 servers since April by targeting open-source AI services.