{"slug": "poellm-compromising-public-ai-servers-for-cryptomining-and-further", "title": "PoeLLM: Compromising Public AI Servers for Cryptomining and Further Reconnaissance", "summary": "Security researchers at Lumen have documented PoeLLM, a Linux malware that exploits internet-exposed instances of LiteLLM, Ollama, Gotenberg, and Gitea to deploy the XMRig and Iron cryptocurrency miners and repurpose compromised servers as scanning and attack delivery nodes. The campaign derives command-and-control IP addresses from a poem hosted on GitHub and connects miners to the Kryptex mining pool, with the LiteLLM vector requiring a valid proxy API key. Administrators are advised to update LiteLLM to 1.83.7 or later, or block access to the /mcp-rest/test/connection and /mcp-rest/test/tools/list endpoints as an interim mitigation.", "body_md": "## \n  \n  \n  1. Basic Information\n\n## \n  \n  \n  2. Executive Summary\n\nPoeLLM is a Linux malware that exploits exposed instances of LiteLLM, Ollama, Gotenberg, Gitea, and others to deploy XMRig and Iron miner, and then repurposes compromised servers as scanning and attack delivery nodes.\n\n## \n  \n  \n  3. Attack Flow\n\n### \n  \n  \n  From Compromise of Exposed Services to Cryptomining and Further Reconnaissance\n\n1. Attackers scan for internet-exposed instances of LiteLLM, Ollama, Gotenberg, Gitea, and other services.\n2. They send exploit requests to vulnerable endpoints to execute the PoeLLM Linux ELF binary.\n3. PoeLLM derives command-and-control (C2) IP addresses from a poem on GitHub and establishes a remote shell.\n4. It launches XMRig or Iron miner and connects to the Kryptex mining pool.\n5. It utilizes selected compromised servers as scanners and exploit delivery workers.\n\n## \n  \n  \n  4. Attacker Positioning and Execution Location\n\n- External attackers who can reach public AI and enterprise services from the internet.\n\n## \n  \n  \n  5. Visibility for Victims and Administrators\n\n- \n**Users** : May experience service delays, increased CPU load, or service unavailability.\n- \n**Administrators** : Can observe unknown ELF binaries, miner pools, GitHub content, C2 ports, and outbound scanning activity.\n\n## \n  \n  \n  6. Success and Failure Conditions\n\n### \n  \n  \n  Success Conditions\n\n- Affected services must be exposed to the internet and running vulnerable versions or insecure configurations.\n- For the LiteLLM CVE-2026-42271 vector, attackers must have access to a valid proxy API key.\n- Linux payloads must be successfully executed, and egress traffic to C2 and mining pools must be permitted.\n\n### \n  \n  \n  Failure Conditions and Mitigations\n\n- Move services behind private networks and update to patched versions. Update LiteLLM to 1.83.7 or later, and as an interim mitigation before updating, block access to `/mcp-rest/test/connection` and`/mcp-rest/test/tools/list` .\n- Rebuild compromised hosts, rotate associated secrets, and monitor for C2 traffic, mining pools, and unauthorized GitHub content retrieval.\n\n## \n  \n  \n  7. Impact Upon Successful Exploitation\n\n- Unauthorized use of CPU and power resources for cryptomining.\n- Execution of additional commands via remote shells.\n- Repurposing of compromised servers into infrastructure for further reconnaissance and exploit delivery.\n- Potential subsequent access to tokens, models, prompts, and connection data stored by AI services.\n\n## \n  \n  \n  8. Observable Logs\n\n- \n**Email** : No email vectors specific to this campaign have been reported.\n- \n**Proxy / SWG / DNS** : Observe HTTP and HTTPS traffic to GitHub dash.css files, payloads, Kryptex endpoints, and known C2 servers.\n- \n**Endpoint / EDR** : Detect PoeLLM ELF binaries, XMRig or Iron miner, shells, scanners, high CPU utilization, and persistence mechanisms.\n- \n**Identity / IdP** : Look for logins from unusual locations, service account usage, and changes to tokens, MFA, or permissions. Investigate subsequent usage even if initial access was unauthenticated.\n- \n**SaaS / Cloud** : Check cloud WAF, load balancers, API audit logs, data access, and large data exports.\n- \n**Network** : Monitor for exploit requests targeting ports such as 3000 and 4000, C2 ports 3778, 5001, 5002, and 9999, mining pool traffic, and scanning activity targeting SSH or login portals.\n\n## \n  \n  \n  9. Determining Attack Success\n\n### \n  \n  \n  Confirmed via Public Information\n\n- \n**Initial Execution Confirmed** : Lumen reported PoeLLM execution on compromised servers. Organizations should correlate service requests with the creation or download of ELF files and their subsequent execution in their own environments.\n- \n**Worker Repurposing Observed** : Lumen observed reconnaissance and exploit delivery originating from some compromised servers. This alone does not indicate successful exploitation on each delivery target.\n\n### \n  \n  \n  Criteria for Internal Assessment\n\n- \n**Malware Execution or Successful Authentication Confirmed** : Confirm PoeLLM execution using host telemetry that identifies the running malware. Correlate C2 connections, remote shells, and miner activity with the responsible processes. A connection to a listed IP address or miner activity alone does not establish PoeLLM execution.\n- \n**Subsequent Compromise Confirmed** : Correlate payload execution, unauthorized authentication, or unauthorized actions on target hosts with attacker requests. Do not judge exploitation as successful based solely on scans or transmitted exploits.\n- Correlate requests, processes, authentication, data access, and outbound traffic to distinguish between attack attempts and successes.\n- Do not infer successful compromise from HTTP status codes or a single alert alone. Corroborate the assessment with evidence from your own environment.\n\n## \n  \n  \n  10. Investigation Playbook\n\n- \n**Investigation Starting Points** : Begin with abnormal requests to public AI services, mining pool traffic, known C2 indicators, unknown ELF binaries, and outbound scanning activity.\n- \n**Initial Verification** : Check target products and versions, external reachability, exposure duration, authentication requirements, and the application timing of mitigations and updates.\n- \n**Endpoint / Server Investigation** : Inspect process trees, service logs, file modifications, persistence mechanisms, shell and miner execution, and outbound communications.\n- \n**Identity / Cloud Investigation** : Review suspicious accounts, tokens, and API usage, privilege changes, and connections or resource access from unusual sources.\n- \n**Subsequent Actions** : Track credential access, lateral movement, additional downloads, data exfiltration, and account creation following the initial event.\n- \n**Containment** : Restrict external reachability and attack vectors, preserve evidence, and then apply updates, rotate credentials, and terminate malicious processes.\n- \n**Classification** : Distinguish between reconnaissance and attack attempts, initial execution, successful authentication, data theft, and subsequent compromise.\n\n## \n  \n  \n  11. Defense and Detection Ideas\n\n- \n**Single Events** : Detect shells or miners spawned from AI service processes, retrieval of GitHub dash.css files, and communication with known C2 servers or Kryptex.\n- \n**Temporal Correlation** : Correlate exploit requests, ELF execution, C2 connections, miner activity, and outbound scanning on the same host.\n- \n**Threat Hunting** : Search for public LiteLLM, Ollama, Gotenberg, or Gitea instances, ports 3000 and 4000, PoeLLM, XMRig, and C2 indicators.\n- \n**Log Limitations** : Ephemeral containers or TLS encryption may obscure processes and URLs. Combine host, container, proxy, and flow logs.\n- \n**Prioritized Mitigations** : Prioritize reducing external exposure, applying updates, rebuilding systems, enforcing egress controls, and rotating secrets.\n\n## \n  \n  \n  12. Facts / Inference / Hypothesis\n\n### \n  \n  \n  Facts\n\n- Lumen has been tracking the PoeLLM campaign since April 2026, confirming activities that compromise exposed AI and enterprise services to distribute Linux ELF malware.\n- Lumen assesses that `/mcp-rest/test/connection` in analyzed samples is likely an entry vector associated with CVE-2026-42271. This CVE affects LiteLLM versions 1.74.2 through 1.83.6 and requires a valid proxy API key. It can be exploited even with low-privilege keys, executing commands with the privileges of the proxy process. How keys were obtained in this campaign remains unconfirmed. Ollama, Gotenberg, and Gitea are also included as targets.\n- PoeLLM features remote shell, HTTP/HTTPS scanner, and exploit delivery capabilities, and executes XMRig and Iron miner. Some compromised servers were repurposed into workers searching for new targets.\n- C2 addresses are derived by converting four words from a poem hosted in a dash.css file on GitHub into an IP address using a hardcoded dictionary. The poem was updated 11 times, and Lumen identified 12 C2 servers, with three active at the time of publication.\n- Lumen reported over 3,400 victim servers in key points and approximately 2,200 in the body text. The difference in aggregation timelines or populations was not explained.\n- Distributed attacks targeting SSH and login portals were also observed, though Lumen assessed at the time of publication that this functionality may still be in early development stages.\n\n### \n  \n  \n  Inference\n\n- Exposing AI tool management APIs to the internet leads not only to miner infections but also risks turning organizational servers into external attack delivery infrastructure, necessitating simultaneous patching and external access restrictions.\n- Because C2 addresses are dynamically derived from a poem on GitHub, blocking solely by known IPs may cause defenders to miss C2 servers after updates occur.\n\n### \n  \n  \n  Hypothesis\n\nNo additional hypotheses. Unconfirmed items are listed in section 14, \"Uncertainties and Additional Investigation.\"\n\n## \n  \n  \n  13. MITRE ATT&CK Mapping\n\n| ID | Technique | Confidence | Basis | \n| T1190 | Exploit Public-Facing Application | high | Lumen assesses that exploitation of LiteLLM MCP endpoints is a likely entry vector, and exploits targeting public AI infrastructure were observed. | \n| T1496.001 | Resource Hijacking: Compute Hijacking | high | XMRig and Iron miner are executed on compromised servers. | \n\n## \n  \n  \n  14. Uncertainties and Additional Investigation\n\n- The aggregation scope, timelines, and deduplication methods behind the figures of over 3,400 versus approximately 2,200 victim servers.\n- The extent to which intrusions via Ivanti Sentry and CVE-2026-10520 were proven on individual victim servers.\n- The completeness, success counts, and credential utilization status of the distributed brute-force functionality.\n- Definitive actor attribution remains unconfirmed. Based on Italian-language artifacts and network evidence, Lumen assessed with moderate confidence that 185.119.19[.]171 served as an administrative interface for C2 infrastructure and botnet operations. That confidence rating concerns the server's role, not the actor's identity or nationality.\n\n## \n  \n  \n  15. Impact on SOCs and Organizations\n\nOrganizations running test instances of LiteLLM or Ollama that fall outside asset inventories and patch management and become exposed to the internet risk having their servers used for both cryptomining and external attacks. Treat AI infrastructure with the same vulnerability management, external exposure reviews, and egress monitoring applied to standard internet-facing applications. Investigate CPU utilization for signs of miners while also checking for scanner activity and C2 update channels.\n\n## \n  \n  \n  16. Summary by Role\n\n- \n**For SOCs** : Correlate exploit requests targeting LiteLLM and other services, PoeLLM execution, mining pools, GitHub dash.css files, C2 ports, and outbound scanning activity.\n- \n**For Administrators** : Isolate target services from the internet and update to patched versions. Rebuild containers and VMs, rotate secrets, and close unused ports.\n- \n**For Users** : General user action is typically not required. Report any abnormal service stoppages or delays in AI services to administrators.", "url": "https://wpnews.pro/news/poellm-compromising-public-ai-servers-for-cryptomining-and-further", "canonical_source": "https://dev.to/anoymask/poellm-compromising-public-ai-servers-for-cryptomining-and-further-reconnaissance-14fl", "published_at": "2026-10-08 00:31:09+00:00", "updated_at": "2026-10-08 00:47:15.903813+00:00", "lang": "en", "topics": ["ai-safety", "ai-infrastructure", "mlops", "ai-tools"], "entities": ["Lumen", "LiteLLM", "Ollama", "Gotenberg", "Gitea", "XMRig", "Iron", "Kryptex"], "also_reported_by": [], "alternates": {"html": "https://wpnews.pro/news/poellm-compromising-public-ai-servers-for-cryptomining-and-further", "markdown": "https://wpnews.pro/news/poellm-compromising-public-ai-servers-for-cryptomining-and-further.md", "text": "https://wpnews.pro/news/poellm-compromising-public-ai-servers-for-cryptomining-and-further.txt", "jsonld": "https://wpnews.pro/news/poellm-compromising-public-ai-servers-for-cryptomining-and-further.jsonld"}}