ConciseSignal
Following

PoeLLM malware infects over 3,400 AI servers for cryptomining

A new malware called PoeLLM has compromised more than 3,400 servers running exposed artificial intelligence and large language model (LLM) services. The malware turns affected servers into scanning and exploitation tools, and installs cryptocurrency miners, connecting them to a Russian service to profit. PoeLLM uses an unusual technique to hide its command-and-control addresses within a poem on GitHub, changing the poem to update locations. Most targets are based in the US and Western Europe.

Why it mattersPoorly secured or publicly exposed AI infrastructure is increasingly being targeted for profitable attacks. PoeLLM’s novel use of a poem to manage malware control channels could complicate detection and mitigation efforts.

Sources covering this

BleepingComputerPoeLLM malware infects exposed AI servers in cryptomining attacks3:04 PM →The Hacker NewsPoeLLM Malware Infects 3,400+ Servers to Expand Crypto Mining Botnet3:33 PM →

In this story

Concise Signal DailyEnterprise AI, security & business tech.Weekdays, 7am Eastern · Sample issue

More in Cybersecurity