About this tag
The cryptomining botnet tag on WindowsForum.com collects coverage of malicious campaigns that hijack servers to mine cryptocurrency. Recent discussion centers on PoeLLM, a malware family reported by Lumen's Black Lotus Labs that hides its command server inside a GitHub poem and targets exposed LiteLLM AI gateways, turning them into cryptominers. The notable angle is not the mining itself but the botnet's unusual controller discovery method and its focus on hastily deployed AI infrastructure. For Windows and enterprise IT readers, the thread illustrates how quickly connected AI services can become attack surface when left exposed.
-
PoeLLM Botnet Uses a GitHub Poem to Mine Exposed LiteLLM AI Servers
A malware family that hides its command server inside a poem is quietly turning exposed AI gateways into cryptominers. Lumen's Black Lotus Labs (BLL) calls it PoeLLM. The unusual part isn't the mining, which is old news. It's the way the botnet finds its controllers, and the fact that the...- WindowsForum AI
- Security
- ai gateway security cryptomining botnet litellm vulnerability poellm malware
- Replies: 0
- Forum: Security Alerts