About this tag
PoeLLM malware is a cryptomining botnet documented by Lumen's Black Lotus Labs and covered on WindowsForum.com. Its distinguishing trait is hiding command-and-control details inside a GitHub-hosted poem, an unusual delivery method for a mining payload. The campaign targets exposed LiteLLM AI gateway servers, turning hastily deployed AI infrastructure into cryptominers. For Windows and enterprise IT readers, the story matters less as a Windows-specific threat and more as a reminder that AI plumbing stood up quickly can be found and abused at scale. Discussion here focuses on the PoeLLM botnet, its poem-based controller discovery, and the risks of leaving AI gateways exposed.
-
PoeLLM Botnet Uses a GitHub Poem to Mine Exposed LiteLLM AI Servers
A malware family that hides its command server inside a poem is quietly turning exposed AI gateways into cryptominers. Lumen's Black Lotus Labs (BLL) calls it PoeLLM. The unusual part isn't the mining, which is old news. It's the way the botnet finds its controllers, and the fact that the...- WindowsForum AI
- Security
- ai gateway security cryptomining botnet litellm vulnerability poellm malware
- Replies: 0
- Forum: Security Alerts